Tag: github
-
Shai-Hulud Attack Nips Cyber-Firm CrowdSec’s GitHub Data
Threat actors stole 170 private repositories using an OAuth token stolen from a former employee’s computer through the TanStack npm supply chain attack. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/shai-hulud-attack-cyber-firm-crowdsec-github-data
-
Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19.The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used…
-
Hackers Compromise 65 GitHub Repositories and Poison npm Package With Hidden Backdoor
Threat actors have compromised at least 65 public GitHub repositories in a software supply-chain campaign that abused npm trusted publishing to distribute a stealthy backdoor through a legitimate package. The malicious package was identified as @dforge-core/dforge-mcp, an MCP-related npm package whose maintainer account was abused for roughly 105 minutes on September 9. Attackers initially pushed…
-
AWS Detects and Quarantines Exposed IAM Credentials in Public GitHub Repositories
AWS can automatically quarantine exposed Identity and Access Management (IAM) access keys that appear in public GitHub repositories. This process involves applying a restrictive managed policy within seconds to reduce the risk of cloud abuse. Researchers from Palo Alto Networks’ Unit 42 documented this response mechanism, showing that AWS employs the AWSCompromisedKeyQuarantine managed policy to…
-
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17.Microsoft’s own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when…
-
Malicious HEIF Upload Reached OpenAI’s Internal GitHub, Researchers Reveal
A malicious HEIF upload exploited Discourse, crossed OpenAI’s identity layer, and reached an internal GitHub repo through a connected Codex account. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/news/news-openai-heif-github-vulnerability/
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
BigDiskBuster Windows Defender DoS Vulnerability Blocks Platform and Signature Updates
A recently published proof-of-concept project named BigDiskBuster claims to prevent Microsoft Defender from completing its platform and security intelligence signature updates. This could create a potential denial-of-service condition, leaving Windows endpoints operating with outdated anti-malware protection. The project, published on GitHub by the user “MSNightmare,” is described as a >>Windows Defender Update Denial of Service…
-
HEIF Heist Image Flaws Let Attackers Gain RCE Across Meta, Slack and GitHub Enterprise
Tags: attack, cyber, data, flaw, github, malicious, rce, remote-code-execution, supply-chain, technology, threat“HEIF Heist,” a broad class of image-processing attack paths that could allow threat actors to turn malicious HEIF, HEIC, and AVIF uploads into remote code execution, sensitive-data exposure, and account compromise across major technology and enterprise platforms. The research, published by Hacktron, highlights a familiar but increasingly dangerous supply-chain weakness: applications often trust native image-decoding…
-
Hackers Exploit TanStack Supply Chain Attack to Steal 170 Private CrowdSec Repositories
Threat actors linked to the TanStack npm supply chain compromise allegedly used a stolen GitHub OAuth token to clone about 170 private CrowdSec repositories, exposing source code, limited contact information, and a restricted AWS notification credential. CrowdSec stated that the compromise originated from a former employee’s account, which remained in the company’s GitHub organization for…
-
Hackers Exploit TanStack Supply Chain Attack to Steal 170 Private CrowdSec Repositories
Threat actors linked to the TanStack npm supply chain compromise allegedly used a stolen GitHub OAuth token to clone about 170 private CrowdSec repositories, exposing source code, limited contact information, and a restricted AWS notification credential. CrowdSec stated that the compromise originated from a former employee’s account, which remained in the company’s GitHub organization for…
-
Hackers Exploit TanStack Supply Chain Attack to Steal 170 Private CrowdSec Repositories
Threat actors linked to the TanStack npm supply chain compromise allegedly used a stolen GitHub OAuth token to clone about 170 private CrowdSec repositories, exposing source code, limited contact information, and a restricted AWS notification credential. CrowdSec stated that the compromise originated from a former employee’s account, which remained in the company’s GitHub organization for…
-
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
An attacker copied about 170 of CrowdSec’s private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18.The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May’s supply chain attack on TanStack, in which malicious versions of…
-
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan.The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation…
-
Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/fake-lastpass-authenticator-github-repos-push-new-rapuncel-infostealer/
-
Researchers used Claude to hack OpenAI
Researchers used Claude to reach an OpenAI employee account and sensitive GitHub data. First seen on arstechnica.com Jump to article: arstechnica.com/ai/2026/09/researchers-used-claude-to-hack-openai/
-
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
A flaw in four widely used AI coding agents lets someone who controls a plugin’s code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday.The firm said Anthropic has patched the flaw in Claude…
-
Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same reach … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/18/plugin4shell-ai-coding-agents-vulnerability/
-
Hardcoded MCP credentials found in public GitHub files
Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/18/hush-security-mcp-credential-exposure-report/
-
Steam Windows Vulnerability Lets Users Escalate Privileges to NT AUTHORITYSYSTEM
A newly published proof of concept called >>BrokenPipe<< has revealed a local privilege escalation vulnerability in the Steam Client Service on Windows systems. According to the project's GitHub repository, this flaw could allow a standard, non-administrative Windows user to make the Steam Client Service launch an executable with NT AUTHORITY\SYSTEM privileges. The proof of concept…
-
AWS’s new sign-up gives accounts spend caps, email invites, and agent-set permissions
New AWS customers can now sign up with a Google, GitHub, or Apple login, start with $100 in Free Tier credits, and build inside a >>project<< where AWS and coding … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/17/aws-spend-limit-agent-set-permissions/
-
Claude Code vs. AWS Kiro vs. GitHub Copilot: Should Every Developer Use the Same AI Coding Tool?
AI coding tools are no longer experimental side projects inside engineering teams. They are becoming part of the software delivery system. GitHub Copilot can plan changes, edit code, execute development tasks, and operate through agent mode. Claude Code can navigate… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/claude-code-vs-aws-kiro-vs-github-copilot-should-every-developer-use-the-same-ai-coding-tool/
-
Novo Nordisk Data Breach Tied to Stolen GitHub Access Tokens
Tags: access, breach, cloud, credentials, cyber, data, data-breach, defense, exploit, extortion, github, group, infrastructureCyber Extortion Group Continues to Target Exposed Cloud-Based Data Over Endpoints. Cyber extortion group FulcrumSec continues to find hardcoded credentials in public-facing IT infrastructure and exploit them as part of what it’s dubbed a Hardcoded Horrorshow that counts Ozempic maker Novo Nordisk among its victims. Here are defenses organizations need to put in place now.…
-
Kimsuky Uses OpenCode AI Agent and GitHub PATs in Operation GitPower Attacks
North Korea-linked threat actor Kimsuky has expanded its Operation GitPower activity with malicious LNK shortcuts, GitHub Personal Access Token (PAT)-authenticated payload delivery, and AI-generated decoy documents linked to the OpenCode coding agent. Genians Security Center analyzed 13 malicious LNK samples collected between August 11 and August 19, 2026. The files were delivered in ZIP archives…
-
Supply Chain of Distrust — Microsoft/GitHub Supply-Chain Compromise Targets AI Developers
Microsoft’s GitHub malware incident exposes a new legal and security reality: AI coding environments are now privileged supply-chain systems, not just productivity tools. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/supply-chain-of-distrust-microsoft-github-supply-chain-compromise-targets-ai-developers/
-
Supply Chain of Distrust — Microsoft/GitHub Supply-Chain Compromise Targets AI Developers
Microsoft’s GitHub malware incident exposes a new legal and security reality: AI coding environments are now privileged supply-chain systems, not just productivity tools. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/supply-chain-of-distrust-microsoft-github-supply-chain-compromise-targets-ai-developers/

