github
184 articles with this tag
MEDIUM
HIGH
INFO
INFO
INFO
CRITICAL
INFO
INFO
HIGH
INFO
MEDIUM
HIGH
LOW
HIGH
HIGH
MEDIUM
MEDIUM
MEDIUM
MEDIUM
HIGH
MEDIUM
INFO
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
CRITICAL
CRITICAL
CRITICAL
MEDIUM
MEDIUM
INFO
MEDIUM
HIGH
CRITICAL
CRITICAL
MEDIUM
HIGH
MEDIUM
MEDIUM
INFO
HIGH
LOW
INFO
CRITICAL
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
HIGH
HIGH
HIGH
INFO
CRITICAL
HIGH
CRITICAL
MEDIUM
MEDIUM
CRITICAL
CRITICAL
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
HIGH
CRITICAL
CRITICAL
HIGH
INFO
HIGH
HIGH
HIGH
CRITICAL
HIGH
HIGH
INFO
HIGH
HIGH
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
HIGH
MEDIUM
HIGH
HIGH
CRITICAL
HIGH
CRITICAL
HIGH
HIGH
HIGH
INFO
CRITICAL
GitHub and PyPI implement new security measures against supply-chain attacks
GitHub delays version updates so malware gets caught first
GitHub, PyPI add time-absed defenses against supply chain attacks
GitHub to implement two-tier bug bounty program amid AI-generated report surge
ThreatsDay: Android Spyware, PLC Attacks, AI Image Prompt Injection + 12 More Stories
GitHub issues $100,000 bounty for critical RCE vulnerability
GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier
Small teams are the heaviest users of AI coding agents
FakeGit campaign uses 7,600 GitHub repos to push SmartLoader malware
AI speeds software development. Is your secret security keeping up?
AI agents tricked into recommending malicious GitHub repositories
FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware
How to use GitHub safely
Threat actor impersonated hundreds of brands on GitHub to push infostealer malware
CVE-2026-50510 GitHub Copilot Remote Code Execution Vulnerability
CVE-2026-47282 GitHub Copilot and Visual Studio Code Information Disclosure Vulnerability
Lessons Learned from CISA’s Recent GitHub Leak
CISA shares postmortem of GitHub credential leak
OpenMandriva Linux project reportedly targeted in attempted sabotage after contributor dispute
Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs
GitHub’s public APIs are becoming an enterprise reconnaissance tool
GitHub Copilot: Sorry Dave, I can't do that harmful thing - unless you ask me in code
GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures
GitHub AI agent leaks private repositories via prompt injection attack
‘GitLost’ prompt injection leaks private repos via GitHub Agentic Workflows
Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection
GitHub AI agent leaks private repos when asked nicely
'GitLost' Flaw Leaks Private Data from GitHub's Agentic Workflows
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data
GitLost: a public GitHub issue can steer an org's Agentic Workflow into leaking private repo contents, and a one-word prefix ("Additionally") bypassed the threat-detection guardrail
Open Source Malware
NCSC-2026-0219 [1.00] [M/H] Kwetsbaarheden verholpen in GitHub Enterprise Server
GitHub’s new tool helps prevent costly open-source license violations
[NEU] [mittel] Microsoft GitHub Enterprise Server: Mehrere Schwachstellen
Clean GitHub repo tricks AI coding agents into running malware
Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns
GitHub Actions hardens checkout security to block ‘pwn request’ attacks
Miasma Worm Source Code Leaked + What NPM v12 Means for Developers | Threat Wire
Novo Nordisk Breach Exposes Software Development Pipeline Risk
Retro gaming fans are the new target for fake GitHub malware
New 42Crunch plugin helps developers find and fix API vulnerabilities in GitHub Copilot
Securing CI/CD in an agentic world: Claude Code Github action case
Free Compromise Detection for GitHub Repos - Tracebit Community Edition
Developers React to the 105-Second Github Chain Reaction | Threat Wire
GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks
The ‘Miasma’ worm source code briefly leaked on GitHub
GitHub announces npm security changes to tackle supply-chain attacks
GitHub pulls pin on npm's auto-run scripts
Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories
Miasma worms its way onto GitHub as attack kit goes open source
GitHub disables Microsoft repos pushing password-stealing malware
For the 2nd time in weeks, Microsoft packages laced with credential stealer
GitHub nukes 70+ Microsoft repos, breaks CI/CD pipelines, following suspected worm infections
GitHub Copilot app launches as desktop home for AI coding agents
Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain Attack
Securing CI/CD in an agentic world: Claude Code Github action case
Claude Code GitHub Action Flaw Let One Malicious Issue Hijack Repositories
Hole in GitHub’s browser-based VSCode editor could lead to stolen token
Another bug hunter leaks Microsoft exploits in defiance of company’s handling of vulnerability disclosures
One-Click GitHub Dev Attack Lets Attackers Steal Full GitHub OAuth Tokens
Why supply chain attacks work and what detection can actually do about it
1-Click GitHub Token Stealing via a VSCode Bug
Poisoning Claude Code: One GitHub Issue to Break the Supply Chain
AI-Generated npm Malware Leaks Its Own GitHub Token
Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft
[NEU] [hoch] Microsoft GitHub Enterprise: Mehrere Schwachstellen ermöglichen Offenlegung von Informationen
Feeding Frenzy: 'Megalodon' Malware Infects Thousands of GitHub Repos
Over 5,500 GitHub Repositories Infected in ‘Megalodon’ Supply Chain Attack
npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks
Packagist Supply Chain Attack Infects 8 Packages Using GitHub-Hosted Linux Malware
Laravel Lang Supply Chain Advisory
TVs, Old York, Flipper One, Ubiquity, Underminr, CISOs, GitHub, Josh Marpet... - SWN #583
HOW CISA leaked public passwords
Megalodon chums the waters in 5.5K+ GitHub repo poisonings
Lawmakers Demand Answers as CISA Tries to Contain Data Leak
Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows
A hacker group is poisoning open source code at an unprecedented scale
Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack
FCC, Github, MiniShai-hulud, Stated of Supply Chain, Itron, CRA, NIS2, and more!! - PSW #927
VS Code WARNING: 3800 repos hacked
Senator urges classified briefing after CISA data leak on GitHub
GitHub Actions Cache Poisoning is eating open source
GitHub ~3,800 internal repos compromised through a malicious VS Code extension
Grafana Labs Says Code Breach Stemmed from TanStack Attack
CVE-2026-45803 gh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection
GitHub links repo breach to TanStack npm supply-chain attack
GitHub Confirms Breach, 4K Internal Repos Stolen
Mini Shai Hulud: Compromised @antv npm packages enable CI/CD credential theft
GitHub says internal repositories were taken in poisoned VS Code extension attack
GitHub hit by a compromised VSCode extension
GitHub confirms breach of 3,800 repos via malicious VSCode extension
Risky Business #838 -- GitHub investigates possible breach
GitHub investigates internal repositories breach claimed by TeamPCP
GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories
CISA credential leak raises alarms, and Capitol Hill demands answers
In stunning display of stupid, secret CISA credentials found in public GitHub repo
America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames
GitHub scales back bug bounties, reminds users security is their responsibility too
GitHub Actions Supply Chain Attack Redirects Tags to Steal CI/CD Credentials