Tag: github
-
Supply Chain of Distrust — Microsoft/GitHub Supply-Chain Compromise Targets AI Developers
Microsoft’s GitHub malware incident exposes a new legal and security reality: AI coding environments are now privileged supply-chain systems, not just productivity tools. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/supply-chain-of-distrust-microsoft-github-supply-chain-compromise-targets-ai-developers/
-
Supply Chain of Distrust — Microsoft/GitHub Supply-Chain Compromise Targets AI Developers
Microsoft’s GitHub malware incident exposes a new legal and security reality: AI coding environments are now privileged supply-chain systems, not just productivity tools. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/supply-chain-of-distrust-microsoft-github-supply-chain-compromise-targets-ai-developers/
-
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon.”FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor,” the researcher said in a GitHub README file, adding First seen on…
-
Fake Claude Opus 5 app delivers malware and wipes its own tracks
A malicious GitHub repository impersonating Anthropic and claiming to offer free access to “Claude Opus 5” is delivering RevStealer, Windows information-stealing malware that … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/01/revstealer-malware-claude-opus-5-github/
-
Malicious npm Package Steals GitHub, Cloud, and CI/CD Secrets and Spreads to Other Packages
A supply-chain compromise affecting the popular npm package @7nohe/openapi-react-query-codegen is exposing developer workstations and CI/CD runners to a credential-stealing, self-propagating payload. On August 28, 2026, attackers published ten malicious versions across every maintained release branch of the OpenAPI-to-TanStack Query code generator, which records roughly 150,000 weekly downloads. The releases appeared in two publishing waves approximately…
-
HardBreacher Exploit Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Privilege Escalation
A proof of concept called HardBreacher allegedly exploits an unpatched local privilege escalation flaw in Kaspersky Antivirus for Endpoint. This vulnerability allows a local user to control a privileged component. The code was published by a GitHub user named MSNightmare and is being presented as a zero-day vulnerability. However, the vendor has not confirmed it.…
-
28,000 Exposed Git Repositories Found Leaking Credentials
Researchers found 28,000 exposed Git repositories containing active AWS, Stripe, OpenAI and GitHub credentials. Learn the risks and defenses. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-28000-exposed-git-repositories-leak-credentials/
-
Patch-Defizit in Deutschland: Exploit gefährdet 85 Prozent aller Exchange-Server
Auf Github ist ein Exploit für eine gefährliche Exchange-Lücke aufgetaucht. Einen Patch gibt es zwar, doch den haben in Deutschland nur wenige installiert. First seen on golem.de Jump to article: www.golem.de/news/patch-defizit-in-deutschland-exploit-gefaehrdet-85-prozent-aller-exchange-server-2608-212397.html
-
Your Coding Assistant Is Shipping Security Vulnerabilities
Tags: access, ai, api, application-security, authentication, compliance, credentials, email, endpoint, framework, github, governance, LLM, programming, risk, service, tool, vulnerabilityYour Coding Assistant Is Shipping Security Vulnerabilities. Here’s How to Fix That. AI coding assistants have gotten remarkably good at writing functional code. Syntax correctness rates are approaching 100%. Developers are more productive than ever. And yet the security picture tells a very different story. Veracode recently evaluated over 150 large language models across vendors…
-
28,000 Exposed .git Repositories Leak Active AWS, OpenAI, Stripe and GitHub Credentials
A large-scale internet scan has uncovered 28,000 publicly accessible .git repositories exposing credentials for AWS, OpenAI, Stripe, GitHub, and other services, illustrating how a basic web server misconfiguration can turn source code history into an immediate cloud access risk. The research, published by attack-surface management firm Intruder, examined 3.5 million live HTTP hosts selected from…
-
Hardening GitHub Actions against pwn requests and token theft
GitHub Actions is a useful automation layer for build, test, release, and operational tasks, but it also creates a new trust boundary. If a workflow is too permissive, an attacker who can influence a pull request, a third-party action, or a runner environment may be able to steal tokens, read secrets, or alter build outputs….…
-
Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE
Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment.The vulnerability (“GHSA-864f-rcv7-6rh4”), which has yet to be assigned a CVE identifier, impacts all versions of the library before and…
-
Critical Snowflake GitHub Actions Flaw Allows Attackers to Steal Internal Jira Credentials
A significant GitHub Actions injection vulnerability in Snowflake’s public snowflake-connector-net repository. This flaw could have allowed unauthenticated attackers to execute commands on a GitHub-hosted runner and potentially steal internal Jira credentials. The vulnerability was discovered by Wiz Red Agent, an autonomous AI-powered security research tool, just five days after the vulnerable workflow was deployed. Snowflake…
-
50,000 Stripe Secrets Leaked in Public Code
Over 50,000 exposed Stripe API keys show how leaked secrets can enable fraud, data access and account abuse within hours. Ransomnews researchers have documented a large-scale leak of Stripe merchant API keys found exposed in public code repositories, GitHub Actions logs, and misconfigured web servers, with over 50,000 unique keys identified in total. The research…
-
Wiz agent finds Snowflake repo flaw in code co-authored by GitHub Copilot Autofix
First seen on scworld.com Jump to article: www.scworld.com/news/wiz-agent-finds-snowflake-repo-flaw-in-code-co-authored-by-github-copilot-autofix
-
Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed
The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/wiz-ai-agent-finds-snowflake/
-
C2Looper v2 Uses GitHub Repositories as Full CommandControl Infrastructure.
C2Looper, a Rust-based backdoor likely associated with a ransomware-related threat actor. A newer build, internally identified as version 2, replaces conventional command-and-control infrastructure with GitHub repositories used to deliver tasks, receive results, maintain beacon records, and host payloads. ThreatLabz identified the malware in July 2026 and assesses, with low-to-medium confidence, that it is delivered through…
-
CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE
Tags: ai, cisa, computing, cybersecurity, exploit, flaw, framework, github, infrastructure, intelligence, kev, open-source, rce, remote-code-execution, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.Ray is an open-source, Python-native distributed computing framework designed to scale artificial intelligence and machine learning workloads. As of writing, the GitHub project has more than First seen…
-
Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection
Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake’s public snowflakedb/snowflake-connector-net repository that it said could be exploited through a crafted GitHub issue to execute commands in a workflow containing internal Jira credentials.The issue was present in .github/workflows/jira_issue.yml, which ran when a First seen on thehackernews.com Jump to article:…
-
C2Looper: A New Backdoor Likely Tied To Ransomware With GitHub C2
IntroductionIn July 2026, Zscaler ThreatLabz identified a new Rust-based malware family that we track as C2Looper, which is likely leveraged by a ransomware-related threat actor. Furthermore, ThreatLabz assesses with low to medium confidence that C2Looper has been delivered to victims through a multi-stage ClickFix infection chain. C2Looper supports backdoor commands including executing arbitrary commands, performing reconnaissance,…
-
Microsoft confirms GitHub is down worldwide
GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-confirms-github-is-down-worldwide/
-
Microsoft confirms GitHub is down worldwide
GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-confirms-github-is-down-worldwide/
-
Mozilla Rotates Firefox and Thunderbird GPG Signing Key After Private GitHub Exposure
Mozilla has rotated a GPG signing subkey used to authenticate release artifacts for Firefox and Thunderbird after an unencrypted copy of the previous subkey was unintentionally committed to a private GitHub repository. The affected signing infrastructure includes selected release files, such as Linux tarballs, RPM packages, and checksum files. Mozilla’s investigation into available audit logs…
-
Nach KI-Hacks: Chinesisches KI-Modell trickst Forscher bei Tests aus
Das KI-Modell Kimi K3 hat bei Tests eine gesicherte Umgebung verlassen und sich die gesuchten Lösungen einfach bei Github beschafft. First seen on golem.de Jump to article: www.golem.de/news/nach-ki-hacks-chinesisches-ki-modell-trickst-forscher-bei-cybertests-aus-2608-211748.html
-
Kimi K3 Reached GitHub During Cybersecurity Test, Exposing Sandbox Gap
Kimi K3 reached GitHub during a cybersecurity test, prompting a dispute over AI guardrails, sandbox configuration, and agent containment. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/artificial-intelligence/news-kimi-k3-github-sandbox-security-test/
-
GitHub Expands Dependabot Malware Alerts to Detect Malicious Packages Across 8 Ecosystems
GitHub has expanded its Dependabot malware alerts beyond npm, enabling the detection of malicious dependencies across various package ecosystems, including PyPI, Maven, RubyGems, NuGet, Go, crates.io, and PHP Composer. This rollout is supported by a new GitHub Advisory Database importer for OpenSSF’s malicious-packages repository, which enhances supply chain detection across these eight ecosystems. GitHub Expands…
-
A GitHub Misconfiguration Let Kimi K3 Cheat a Cybersecurity Benchmark
Kimi K3 bypassed a UK cybersecurity test by accessing GitHub, cloning the benchmark and reading its solutions instead of solving the challenge Sometimes the smartest move isn’t solving the puzzle, it’s noticing nobody locked the door to the answer key. That’s essentially what happened when Moonshot’s Kimi K3 model was put through a cybersecurity evaluation…
-
Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro (“solidity-pro”) that has been observed delivering a browser wallet and credential stealer.The names of the extensions are below – helper-beeps.solidity-pro web3devtoolsx.solidity-proAlthough neither of the extensions is now available on Open VSX, the GitHub repository First seen on thehackernews.com Jump…
-
Nach KI-Hacks: Chinesisches KI-Modell trickst Forscher bei Cybertests aus
Das KI-Modell Kimi K3 hat bei Cybertests seine Sandbox-Umgebung verlassen und sich die gesuchten Lösungen einfach bei Github beschafft. First seen on golem.de Jump to article: www.golem.de/news/nach-ki-hacks-chinesisches-ki-modell-trickst-forscher-bei-cybertests-aus-2608-211748.html

