-
Attackers can silently clone “Verified” GitHub commits by abusing signature malleability in Git’s commit-signing formats, creating byte‑different commits with identical content, valid signatures, and fresh “Verified” badges under new hashes. This break…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A critical vulnerability known as “GitLost” has been discovered in GitHub’s newly introduced Agentic Workflows by Noma Labs. This flaw allows unauthenticated attackers to exfiltrate sensitive data from private repositories. It demonstrates …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Noma Labs details GitLost, a prompt injection flaw that made GitHub’s AI agent expose private repo data through a crafted public issue and guardrail failures.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A widescale escalation in the PolinRider supply‑chain campaign: threat actors have compromised GitHub maintainer accounts to publish infected package versions across multiple ecosystems. The investigation identified 162 malicious release artifacts acro…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A coordinated supply-chain campaign has been weaponizing GitHub proof-of-concept (PoC) repositories to compromise vulnerability researchers and penetration testers, delivering a stealthy Python Remote Access Trojan (RAT) dubbed “ChocoPoC.” The lure is …
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
Novee Security reveals Cordyceps, a CI/CD vulnerability in GitHub Actions workflows that let anonymous users poison builds and expose tokens across major projects today.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A multi-platform malware campaign abuses fake trust signals to infect Windows and Mac users with a crypto clipper packed with 15,500 attacker wallets.
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
GitHub has implemented a major security enhancement in its Actions ecosystem with the release of actions/checkout v7, which aims to address a long-standing class of vulnerabilities known as “pwn requests.” This update was announced on June 18, 2026, an…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A large-scale malware distribution campaign utilizing GitHub repositories has been uncovered. This coordinated effort weaponized over 10,000 repositories to deliver Trojanized payloads. The activity was first identified on June 18, 2026, and highlights…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶
-
A sophisticated, long-running phishing operation has evolved into a serverless, modular campaign that weaponizes GitHub Pages to harvest payment card data, credentials, and customer identifiers from banking customers in Mexico. The campaign’s architect…
¶¶¶¶¶
¶¶¶¶¶
¶¶¶¶¶


