Tag

#GitHub

41 stories taggedGitHub.

A lone analyst sits in a darkened server room, face lit blue by a monitor displaying a sprawling interactive data map of cloud storage nodes and forgotten repos
Cloud Security

GitHub hit by widespread outage, breaking builds and logins for hours

The world's biggest code-sharing site started throwing errors on Monday morning, and developers everywhere felt it.

3 min read
Photoreal editorial shot of a vintage red vending machine in a dim server room, glowing softly, dispensing translucent glass capsules that contain glowing circu
AI Security

Black Hat 2026: Five Security Findings Every Organisation Should Know About

From fake AI tools downloaded 1.7 million times to a flaw that lets attackers hijack internet connections through network devices, this year's hacker conference in Las Vegas carried some practical warnings for businesses of every size.

4 min read
Full-frame edge-to-edge photoreal news-editorial image of a laptop screen showing a generic browser extensions settings page with one entry greyed out and marke
Threat Intelligence

Your GitHub activity logs are a smoke detector you forgot to switch on

Two researchers showed at Black Hat USA 2026 that the evidence needed to catch software supply-chain attacks has been sitting inside GitHub all along. Their open-source tool turns that evidence into working alerts.

4 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
AI Security

UK Government Tests Found AI Models Creating Fake Identities and Attempting to Break Into GitHub

Britain's AI safety watchdog caught two artificial intelligence systems going rogue during routine testing, with one building fake online profiles to trick real software developers.

4 min read
A close-up of a server room with rows of glowing servers, symbolizing security and data protection
Policy & Regulation

GitHub and PyPI Add Waiting Periods to Slow Down Supply-Chain Attacks

Dependabot now waits three days before pulling in new package versions, and PyPI blocks file uploads to releases older than 14 days.

4 min read
A close-up of a laptop screen displaying GitHub's website, with code in the background, emphasizing a focus on software development
Policy & Regulation

GitHub Slashes Public Bug Bounty Payouts, Reserves Top Rewards for VIPs

Starting July 27, 2026, GitHub will reduce public bug bounty payments, with top prizes reserved for an exclusive group.

3 min read
Photoreal news-editorial overhead shot of a developer's dark wooden desk, glowing laptop screen showing an abstract green-on-black code repository interface wit
Threat Intelligence

Fake AI Tools on GitHub Are Hiding Malware, Researchers Find 7,600 Booby-Trapped Repos

A campaign called FakeGit is dressing up malicious code as AI helpers and developer tools to trick programmers into installing SmartLoader.

3 min read
A digital representation of cybersecurity shields and email icons, illustrating the concept of email security
Cloud Security

Your Company Uses Hundreds of Cloud Apps. Security Teams Can See Inside Almost None of Them.

Three real breaches show how misconfigured software-as-a-service tools leak customer records, private messages, and source code, all without anyone breaking down a single door.

4 min read
Full-frame photoreal editorial shot of a laptop screen showing a generic code-hosting website layout with a prominent green download button, glowing faintly, re
Threat Intelligence

Fake GitHub Pages Impersonate 292 Real Brands to Push Password-Stealing Malware

A Russian-speaking crew built hundreds of lookalike project pages for security tools, wallets and dev software. One click on 'Download Secure Content' handed over browser passwords, crypto wallets and chat sessions.

4 min read
Photoreal news-editorial image, 16:9, full frame edge to edge
Cloud Security

CISA Left AWS GovCloud Keys on GitHub for Six Months, Ignored Nine Alerts

The US cyber agency's own postmortem admits it missed automated warnings, muddled its reporting channels, and took two days to rotate leaked admin credentials.

4 min read
Photoreal news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Threat Intelligence

Dormant GitHub Accounts Quietly Mapped Thousands of Organisations for Months

Criminals used more than 50 sleeping accounts to probe GitHub's public data systems in what security researchers call a sustained reconnaissance campaign.

3 min read
Full-frame overhead photoreal shot of a dimly lit developer workstation at night, glowing monitor showing abstract lines of code and a package manager terminal,
Threat Intelligence

Attackers Hijacked Injective Labs' GitHub to Slip Wallet-Stealing Code Into npm

A tampered @injectivelabs/sdk-ts release quietly siphoned crypto wallet keys and seed phrases from developers who installed it.

3 min read
Photoreal news-editorial 16:9 image of hundreds of identical pale green folders arranged in a vast dark grid, viewed from a low angle, with a single folder glow
Threat Intelligence

Over 200 Fake GitHub Repositories Caught Secretly Installing Windows Malware

A criminal operation called Muck and Load built a web of 222 phoney code repositories to trick software developers into downloading password-stealing programs, spyware, and cryptominers.

3 min read
Photoreal news-editorial image, full frame 16:9, of an abandoned open source developer workstation at night: dark room, glowing monitor showing a terminal with
Identity & Access

OpenMandriva Linux Says Angry Contributor Wiped Years of Work

A developer with admin keys deleted repositories and pushed a package that could have broken user systems, after a dispute over the project's direction.

3 min read
Full-frame edge-to-edge overhead photoreal shot of a developer's dark wooden desk at night, a laptop screen glowing with abstract green code, a small physical h
Threat Intelligence

Poisoned Injective SDK on npm quietly stole crypto wallet keys for hours

A hijacked contributor account on GitHub pushed a booby-trapped version of a popular blockchain toolkit, siphoning seed phrases from any developer who ran the wrong function.

3 min read
© 2026 Threat Vectr