-
Attackers have been observed abusing GitHub Actions workflows to distribute provenance-signed malicious npm packages, marking a significant escalation in software supply chain threats. On July 14, 2026, Microsoft Threat Intelligence uncovered a coordin…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Operation STANDOFF is a Russian‑speaking cybercriminal campaign that uses a cluster of at least 44 TimeWeb‑hosted servers that all masquerade as benign GitHub redirectors to conceal multi‑malware command‑and‑control (C2) and proxy traffic. This infrast…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
GitHub has introduced a default cooldown period for Dependabot version updates to decrease the risk of organizations automatically adopting malicious or compromised open-source dependencies as soon as they are released. This change comes in response to…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Hackers are abusing compromised GitHub repositories and GitHub Actions workflows to build a de facto global botnet that scans and exploits web hosting servers, with a primary focus on cPanel and WHM deployments. The campaign first surfaced when malicio…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Attackers can silently clone “Verified” GitHub commits by abusing signature malleability in Git’s commit-signing formats, creating byte‑different commits with identical content, valid signatures, and fresh “Verified” badges under new hashes. This break…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical vulnerability known as “GitLost” has been discovered in GitHub’s newly introduced Agentic Workflows by Noma Labs. This flaw allows unauthenticated attackers to exfiltrate sensitive data from private repositories. It demonstrates …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Noma Labs details GitLost, a prompt injection flaw that made GitHub’s AI agent expose private repo data through a crafted public issue and guardrail failures.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A widescale escalation in the PolinRider supply‑chain campaign: threat actors have compromised GitHub maintainer accounts to publish infected package versions across multiple ecosystems. The investigation identified 162 malicious release artifacts acro…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A coordinated supply-chain campaign has been weaponizing GitHub proof-of-concept (PoC) repositories to compromise vulnerability researchers and penetration testers, delivering a stealthy Python Remote Access Trojan (RAT) dubbed “ChocoPoC.” The lure is …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Novee Security reveals Cordyceps, a CI/CD vulnerability in GitHub Actions workflows that let anonymous users poison builds and expose tokens across major projects today.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


