Tag: Github


  • Wiz AI Agent Finds Snowflake GitHub Actions Flaw

    An autonomous AI security agent from Wiz found and exploited a Snowflake GitHub Actions flaw that exposed a credential for an internal Jira system. The vulnerability allowed unauthenticated users to run commands by submitting a GitHub issue with a specially crafted title. Snowflake fixed the issue and rotated the affected credential after Wiz reported it.…

  • GitHub Outage Causes Errors Across Website, API and Actions

    GitHub is experiencing a widespread outage that is affecting its website, API, Actions, Pull Requests, authentication tools and other services. Microsoft confirmed the issue on 17 August 2026 and says it is working to reduce the impact. The incident is disrupting several tools that developers use to host code, manage projects and run automated software…

  • GitHub and PyPI Add Time-Based Supply Chain Defences

    GitHub and PyPI have introduced new time-based supply chain defences to limit the impact of malicious package releases. GitHub’s Dependabot now applies a default three-day delay before updating dependencies. Meanwhile, PyPI will block new files from being added to releases older than 14 days. Both measures aim to reduce the window for software supply chain…

  • Fake GitHub Repositories Spread BoryptGrab Infostealer Through Trusted Software Downloads

    A large-scale campaign using fake GitHub repositories is distributing infostealer malware disguised as trusted software projects. The malicious repositories imitate well-known applications and security tools, tricking users into downloading malware instead of legitimate software. Researchers uncovered hundreds of fake repositories that targeted developers, cryptocurrency users, gamers, and anyone searching for popular security or productivity tools. Nearly 300…

  • GitHub Repository Trick Can Fool AI Coding Agents Into Running Hidden Malware

    Security researchers have demonstrated a new attack technique that could trick AI coding agents into executing hidden malware, even when a GitHub repository appears completely legitimate. Researchers at Mozilla’s Zero Day Investigative Network (0DIN) say the method exploits how AI-powered coding assistants automatically troubleshoot software installation problems. Instead of relying on malicious code inside a…

  • Dynatrace Source Code Allegedly Stolen in GitHub Breach

    A threat actor claims to have stolen Dynatrace source code and internal GitHub repositories in a breach that could expose sensitive infrastructure information. The alleged dataset contains 246 repositories and reportedly includes source code, deployment configurations, and cloud environment details. While Dynatrace has not confirmed the claims, security researchers who reviewed published samples believe parts…

  • GitHub VSCode Breach Exposed Source Code and Secrets

    A security incident involving a compromised Visual Studio Code extension has raised fresh concerns about software supply chain attacks targeting developer ecosystems. Researchers discovered that attackers abused extension infrastructure connected to GitHub workflows to expose source code, authentication secrets, and sensitive development data from affected systems. The breach highlights how trusted developer tools continue becoming…

  • CISA GitHub Leak Exposed AWS Tokens and Passwords

    A major security incident involving the US Cybersecurity and Infrastructure Security Agency has sparked concern across the cybersecurity industry. Researchers discovered a public GitHub repository containing plaintext passwords, AWS GovCloud tokens, internal deployment files, and authentication credentials tied to CISA infrastructure. The exposed repository reportedly stayed public for months before researchers pushed for its removal.…

  • GitHub vulnerability risks millions of repositories

    A critical GitHub vulnerability has raised serious concerns across the developer community. Researchers discovered a flaw that could allow attackers to interfere with repositories using a crafted request. The issue affects both cloud-hosted environments and self-managed deployments, increasing its overall impact. Crafted git push could trigger code execution The GitHub vulnerability involves improper handling of…

  • Self-hosted GitHub alternative launched in Netherlands

    The Netherlands has introduced a self-hosted GitHub alternative to strengthen control over public sector software. The move reflects rising concern about relying on external platforms for critical development work. Government shifts away from external platforms Dutch authorities created the platform to host open-source projects developed within government institutions. The goal is to reduce dependence on…