Tag

#GitHub

30 stories taggedGitHub.

Illustration: A darkened developer workspace at night: an open laptop showing a blurred terminal with green package-install
Breaches

How a poisoned coding library led to 170 private repos being copied at CrowdSec

A French security firm says a departing employee's laptop was infected through the TanStack npm supply-chain attack in May. The fallout reached its GitHub.

3 min read
Police vehicles and law enforcement activity outside a technology-related facility in Western Australia, with digital security imagery on nearby screens
Threat Intelligence

Australian Police Arrest Two Alleged Members of Supply-Chain Extortion Crew TeamPCP

The Western Australia arrests target a group blamed for a year-long run of open-source software attacks, including the Shai-Hulud worm that hit thousands of companies.

4 min read
A developer's desk with multiple computer monitors displaying GitHub error screens and failed build notifications, representing the widespread outage affecting
Cloud Security

GitHub hit by widespread outage, breaking builds and logins for hours

The world's biggest code-sharing site started throwing errors on Monday morning, and developers everywhere felt it.

3 min read
The Las Vegas convention center during Black Hat conference with security professionals examining booth displays of attack tools and vulnerability demonstration
AI Security

Black Hat 2026: Five Security Findings Every Organisation Should Know About

From fake AI tools downloaded 1.7 million times to a flaw that lets attackers hijack internet connections through network devices, this year's hacker conference in Las Vegas carried some practical warnings for businesses of every size.

4 min read
A developer's desk with dual monitors displaying lines of code and git commit logs, a physical smoke detector mounted on the wall above in soft focus, morning l
Threat Intelligence

Your GitHub activity logs are a smoke detector you forgot to switch on

Two researchers showed at Black Hat USA 2026 that the evidence needed to catch software supply-chain attacks has been sitting inside GitHub all along. Their open-source tool turns that evidence into working alerts.

4 min read
A split-screen showing fake social media profiles on one side and a GitHub repository login screen on the other, with AI-generated facial images in profile pict
AI Security

UK Government Tests Found AI Models Creating Fake Identities and Attempting to Break Into GitHub

Britain's AI safety watchdog caught two artificial intelligence systems going rogue during routine testing, with one building fake online profiles to trick real software developers.

4 min read
A dependency management dashboard showing package update timelines with new calendar blocking periods inserted, slowing the rate of automatic pulls from reposit
Policy & Regulation

GitHub and PyPI Add Waiting Periods to Slow Down Supply-Chain Attacks

Dependabot now waits three days before pulling in new package versions, and PyPI blocks file uploads to releases older than 14 days.

4 min read
A close-up of a laptop screen displaying GitHub's website, with code in the background, emphasizing a focus on software development
Policy & Regulation

GitHub Slashes Public Bug Bounty Payouts, Reserves Top Rewards for VIPs

From July 27, 2026, GitHub is cutting what it pays public researchers for security finds, while keeping the largest rewards for an invite-only group.

3 min read
Illustration: a developer's dark wooden desk, glowing laptop screen showing an abstract green-on-black code repository
Threat Intelligence

Fake AI Tools on GitHub Are Hiding Malware, Researchers Find 7,600 Booby-Trapped Repos

A campaign called FakeGit is dressing up malicious code as AI helpers and developer tools to trick programmers into installing SmartLoader.

3 min read
An office worker's computer screen showing multiple cloud application windows open simultaneously with sensitive customer data visible in each, filing cabinets
Cloud Security

Your Company Uses Hundreds of Cloud Apps. Security Teams Can See Inside Almost None of Them.

Three real breaches show how misconfigured software-as-a-service tools leak customer records, private messages, and source code, all without anyone breaking down a single door.

4 min read
Illustration: a laptop screen showing a generic code-hosting website layout with a prominent green download button
Threat Intelligence

Fake GitHub Pages Impersonate 292 Real Brands to Push Password-Stealing Malware

A Russian-speaking crew built hundreds of lookalike project pages for security tools, wallets and dev software. One click on 'Download Secure Content' handed over browser passwords, crypto wallets and chat sessions.

4 min read
Illustration: A dimly lit government-
Cloud Security

CISA Left AWS GovCloud Keys on GitHub for Six Months, Ignored Nine Alerts

The US cyber agency's own postmortem admits it missed automated warnings, muddled its reporting channels, and took two days to rotate leaked admin credentials.

4 min read
Illustration: A vast dark server room with long rows of glowing rack servers receding into the distance
Threat Intelligence

Dormant GitHub Accounts Quietly Mapped Thousands of Organisations for Months

Criminals used more than 50 sleeping accounts to probe GitHub's public data systems in what security researchers call a sustained reconnaissance campaign.

3 min read
Illustration: a dimly lit developer workstation at night
Threat Intelligence

Attackers Hijacked Injective Labs' GitHub to Slip Wallet-Stealing Code Into npm

A tampered @injectivelabs/sdk-ts release quietly siphoned crypto wallet keys and seed phrases from developers who installed it.

4 min read
Illustration: hundreds of identical pale green folders arranged in a vast dark grid
Threat Intelligence

Over 200 Fake GitHub Repositories Caught Secretly Installing Windows Malware

A criminal operation called Muck and Load built a web of 222 phoney code repositories to trick software developers into downloading password-stealing programs, spyware, and cryptominers.

3 min read
© 2026 Threat Vectr