Crying Out Cloud

Hacking GitHub with a Semicolon & Claude with Sagi Tzadik


Listen Later

Wiz researcher Sagi Tzadik joins us to break down how a single semicolon led to a critical Remote Code Execution (RCE) vulnerability in GitHub.


For two years, Sagi sat on a lead. Reverse engineering GitHub's microservices manually was too tedious to justify the time. Then, AI agents arrived. By hooking Claude directly into his reverse engineering software, he condensed months of grueling binary analysis into 48 hours. The result? A critical bug in how GitHub handles git push options that exposed both SaaS and Enterprise environments. We get into the weeds on how different microservices interpreting the same input differently creates massive attack surfaces, and why security by obscurity is officially dead in the age of AI.


What's Inside:

- How combining Claude with the IDA MCP server dramatically sped up the reverse engineering process

- The technical anatomy of the GitHub semicolon vulnerability.

- Why microservice communication breakdowns lead to critical RCEs.

- The massive difference in impact between GitHub.com and GitHub Enterprise Server.

- Why Enterprise users need to patch their instances immediately.


Resources:

- Learn more about the findings at: https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854

...more
View all episodesView all episodes
Download on the App Store

Crying Out CloudBy Wiz

  • 4.8
  • 4.8
  • 4.8
  • 4.8
  • 4.8

4.8

21 ratings


More shows like Crying Out Cloud

View all
This American Life by This American Life

This American Life

91,297 Listeners

Hidden Brain by Hidden Brain, Shankar Vedantam

Hidden Brain

43,687 Listeners

Risky Business by Risky Business Media

Risky Business

371 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

651 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,028 Listeners

The Daily by The New York Times

The Daily

113,121 Listeners

Screaming in the Cloud by Corey Quinn

Screaming in the Cloud

92 Listeners

Hacking Humans by N2K Networks

Hacking Humans

315 Listeners

CISO Series Podcast by David Spark, Mike Johnson, and Andy Ellis

CISO Series Podcast

195 Listeners

Practical AI by Practical AI LLC

Practical AI

212 Listeners

Three Buddy Problem by Security Conversations

Three Buddy Problem

61 Listeners

Risky Bulletin by Risky Business Media

Risky Bulletin

45 Listeners

Prof G Markets by Vox Media Podcast Network

Prof G Markets

1,480 Listeners