Russian hackers are trying to sneak infostealers onto people's devices to grab passwords, crypto, and more.
Researchers uncover 7,600 FakeGit GitHub repos, including 800 AI skills and MCP lures spreading SmartLoader malware.
A threat actor has published hundreds of fake GitHub repositories impersonating legitimate software and security projects to ...
Attackers created at least 292 fake GitHub repositories that impersonated developer tools and redirected users to ...
The issue affects GitHub Agentic Workflows setups that read public input, hold private repo access, and can post output ...
GitHub confirmed on May 20 that a poisoned VS Code extension installed on an employee’s device gave attackers access to roughly 3,800 internal repositories at the Microsoft-owned code storage and ...
An unknown user going by the handle "Gitloker" is grabbing and wiping clean repositories on GitHub in an apparent effort to extort victims. The campaign, which a researcher at Chilean cybersecurity ...
A prompt injection attack can trick GitHub’s preview Agentic Workflows into retrieving content from private repositories and ...
Millions of GitHub repositories may be vulnerable to dependency repository hijacking, also known as "RepoJacking," which could help attackers deploy supply chain attacks impacting a large number of ...
GitHub Actions security enforcement went live today: actions/checkout now refuses by default to execute untrusted fork code ...
Millions of enterprise software repositories on GitHub are vulnerable to repojacking, a relatively simple kind of software supply chain attack where a threat actor redirects projects that are ...