URL has been copied successfully!
Attackers Can Generate Duplicate Verified GitHub Commits Using Signature Malleability
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Attackers Can Generate Duplicate Verified GitHub Commits Using Signature Malleability

Attackers can silently clone “Verified” GitHub commits by abusing signature malleability in Git’s commit-signing formats, creating byte”‘different commits with identical content, valid signatures, and fresh “Verified” badges under new hashes. This breaks the long”‘standing assumption that a verified commit hash is a unique, immutable identifier for a specific piece of signed content and exposes hash”‘based […] The post Attackers Can Generate Duplicate Verified GitHub Commits Using Signature Malleability appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.

First seen on gbhackers.com

Jump to article: gbhackers.com/duplicate-verified-github-commits-using-signature-malleability/

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link