Tag: github
-
Malware Distribution Service Exploits Thousands of GitHub Accounts
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/malware-distribution-service-exploits-thousands-of-github-accounts
-
3,000 GitHub accounts found distributing malware
First seen on scmagazine.com Jump to article: www.scmagazine.com/news/3000-github-accounts-found-distributing-malware
-
Over 3,000 GitHub accounts used by malware distribution service
Threat actors known as ‘Stargazer Goblin’ have created a malware Distribution-as-a-Service (DaaS) from over 3,000 fake accounts on GitHub that push in… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/over-3-000-github-accounts-used-by-malware-distribution-service/
-
Google, Microsoft, Others Support U.S.-Based Spyware Lawsuits
Microsoft and Google were joined by LinkedIn, GitHub, and Trend Micro in a supporting an appeal of a lawsuit against spyware maker NSO Group that was … First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/google-microsoft-others-support-u-s-based-spyware-lawsuits/
-
Network of 3,000 GitHub Accounts Used for Malware Distribution
Stargazer Goblin has created a network of over 3,000 GitHub accounts to distribute malware through phishing repositories. The post Network of 3,000 Gi… First seen on securityweek.com Jump to article: www.securityweek.com/network-of-3000-github-accounts-used-for-malware-distribution/
-
GitHub Token Leak Exposes Python’s Core Repositories to Potential Attacks
Cybersecurity researchers said they discovered an accidentally leaked GitHub token that could have granted elevated access to the GitHub repositories … First seen on thehackernews.com Jump to article: thehackernews.com/2024/07/github-token-leak-exposes-pythons-core.html
-
Nach Yuzu: Nintendo lässt weitere Switch-Emulatoren sperren
Insgesamt 14 Github-Repos von Switch-Emulatoren sind nicht mehr verfügbar. Laut Nintendo griffen sie alle zumindest zum Teil auf Code von Yuzu zurück…. First seen on golem.de Jump to article: www.golem.de/news/nach-yuzu-nintendo-laesst-weitere-switch-emulatoren-sperren-2407-187022.html
-
Most GitHub Actions workflows are insecure in some way
Tags: githubMost GitHub Actions are susceptible to exploitation; they are overly privileged or have risky dependencies, according to Legit Security. GitHub Action… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/07/17/insecure-github-actions-workflows/
-
Python Repositories Threatened by Inadvertently Exposed GitHub Token
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/python-repositories-threatened-by-inadvertently-exposed-github-token
-
Trojanized jQuery Packages Found on npm, GitHub, and jsDelivr Code Repositories
Unknown threat actors have been found propagating trojanized versions of jQuery on npm, GitHub, and jsDelivr in what appears to be an instance of a co… First seen on thehackernews.com Jump to article: thehackernews.com/2024/07/trojanized-jquery-packages-found-on-npm.html
-
Ex-GitHub Engineers Raise $20M to Enhance Pen-Testing with AI-Powered XBOW
A team of former GitHub engineers has secured $20 million in venture capital funding from Sequoia to build AI-powered security tools. The post Ex-GitH… First seen on securityweek.com Jump to article: www.securityweek.com/ex-github-engineers-raise-20m-to-enhance-pen-testing-with-ai-powered-xbow/
-
Trojanized jQuery Packages Spread via ‘Complex’ Supply Chain Attack
The campaign, which distributes dozens of malicious jQuery variants across npm, GitHub, and jsDelivr, appears to be a manual effort, and lacks the typ… First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/trojanized-jquery-packages-complex-supply-chain-attack
-
Trojanized jQuery Infiltrates npm, GitHub, and CDNs: Thousands of Packages at Risk
First seen on hackread.com Jump to article: hackread.com/trojanized-jquery-threatens-npm-github-and-cdns/
-
Passkey Redaction Attacks Subvert GitHub, Microsoft Authentication
Adversary-in-the-middle attacks can strip out the passkey option from login pages that users see, leaving targets with only authentication choices tha… First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/passkey-redaction-attacks-subvert-github-microsoft-authentication
-
Secrets Exposed: The Rise of GitHub as an Attack Vector
A Look at Chariot’s Capability to Protect On June 6, 2024, an anonymous user posted nearly 300 GB of stolen source code to 4chan. Per the user, the le… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/secrets-exposed-the-rise-of-github-as-an-attack-vector/
-
Dev rejects CVE severity, makes his GitHub repo read-only
The popular open source project, ‘ip’ had its GitHub repository archived, or made read-only by its developer as a result of a dubious CVE report filed… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/dev-rejects-cve-severity-makes-his-github-repo-read-only/
-
Xeno RAT Attacking Users Via GitHub Repository And .gg Domains
Threat actors use RATs because they provide attackers with persistent access to compromised systems, enabling long-term espionage and exploitation. No… First seen on gbhackers.com Jump to article: gbhackers.com/xeno-rat-attacks-via-github-gg-domains/
-
Guest Blog: Ox Security on learning from the Recent GitHub Extortion Campaigns
A new threat actor group known as Gitloker has launched an alarming campaign that wipes victims’ GitHub repositories and attempts to extort them. Vict… First seen on itsecurityguru.org Jump to article: www.itsecurityguru.org/2024/06/13/guest-blog-proactive-application-security-learning-from-the-recent-github-extortion-campaigns
-
Week in review: JetBrains GitHub plugin vulnerability, 20k FortiGate appliances compromised
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Users of JetBrains IDEs at risk of GitHub access tok… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/16/week-in-review-jetbrains-github-plugin-vulnerability-20k-fortigate-appliances-compromised/
-
New York Times Internal Data Nabbed From GitHub
The tranche of data, lifted from underprotected GitHub repositories, reportedly includes source code, though the country’s paper of record has not yet… First seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/new-york-times-internal-data-nabbed-from-github
-
Weekly Vulnerability Report: Critical Security Flaws Identified by Cyble in GitHub, FortiOS, and PHP
The Cyber Express, in collaboration with r Express, in collaboration with Cyble Research & Intel… First seen on thecyberexpress.com Jump to article: https://thecyberexpress.com/weekly-vulnerability-report-security-flaws/
-
GitHub Repos Targeted in Cyber-Extortion Attacks
First seen on darkreading.com Jump to article: www.darkreading.com/application-security/github-repos-targeted-in-cyber-extortion-attacks
-
Angriffswelle: Hacker löscht Github-Repos und fordert Lösegeld
Für die Kontaktaufnahme verweist der Angreifer auf Telegram. Er gibt sich als Analyst für Cybervorfälle aus und behauptet, ein Back-up erstellt zu hab… First seen on golem.de Jump to article: www.golem.de/news/angriffswelle-hacker-loescht-github-repos-und-fordert-loesegeld-2406-185827.html
-
JetBrains fixed IntelliJ IDE flaw exposing GitHub access tokens
JetBrains warned to fix a critical vulnerability in IntelliJ integrated development environment (IDE) apps that exposes GitHub access tokens. JetBrain… First seen on securityaffairs.com Jump to article: securityaffairs.com/164466/security/jetbrains-fixed-intellij-ide-flaw.html
-
New York Times warns freelancers of GitHub repo data breach
The New York Times notified an undisclosed number of contributors that some of their sensitive personal information was stolen and leaked after its Gi… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-york-times-warns-freelancers-of-github-repo-data-breach/
-
GitHub phishing campaign wipes repos, extorts victims
First seen on scmagazine.com Jump to article: www.scmagazine.com/news/github-phishing-campaign-wipes-repos-extorts-victims
-
JetBrains Warns of GitHub Plugin that Exposes Access Tokens
A critical vulnerability (CVE-2024-37051) in the JetBrains GitHub plugin for IntelliJ-based IDEs (2023.1 and later) exposed access tokens to malicious… First seen on gbhackers.com Jump to article: gbhackers.com/jetbrains-github-plugin-flaw/
-
GitHub Paid Out Over $4 Million via Bug Bounty Program
The code hosting platform GitHub has paid out more than $4 million since the launch of its bug bounty program 10 years ago. The post hosting platform … First seen on securityweek.com Jump to article: www.securityweek.com/github-paid-out-over-4-million-via-bug-bounty-program/
-
JetBrains warns of IntelliJ IDE bug exposing GitHub access tokens
JetBrains warned customers to patch a critical vulnerability that impacts users of its IntelliJ integrated development environment (IDE) apps and expo… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/jetbrains-warns-of-intellij-ide-bug-exposing-github-access-tokens/

