Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

GitHub

20 articles

GBHackers general GitHub Linux 13h ago

BlackTech APT Uses New BlueShell Linux Backdoor in Attacks on Japanese Organizations

BlackTech, a long-running China-aligned APT group, has adopted a new Linux backdoor built on the BlueShell open-source RAT to conduct post-intrusion operatio...

GBHackers → Details

Help Net Security general GitHub 2d ago

1Password targets standing privileges with new access management capabilities

1Password has launched 1Password Privileged Access, extending the 1Password Unified Access platform with privileged access management (PAM). It enables just-...

Help Net Security → Details

GBHackers general GitHub 3d ago

Operation STANDOFF Uses GitHub Redirects Across 44 Servers to Hide Multi-Malware C2 Traffic

Operation STANDOFF is a Russian‑speaking cybercriminal campaign that uses a cluster of at least 44 TimeWeb‑hosted servers that all masquerade as benign GitHu...

GBHackers → Details

SC Media general GitHub 4d ago

GitHub and PyPI implement new security measures against supply-chain attacks

Based on information from Bleeping Computer, GitHub and the Python Package Index (PyPI) have introduced new time-based security mechanisms within their devel...

SC Media → Details

SecurityWeek general GitHub 4d ago

New GitHub, PyPI Policies Boost Supply Chain Security

Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days. The post New GitHub, ...

SecurityWeek → Details

GBHackers general GitHub 4d ago

GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies

GitHub has introduced a default cooldown period for Dependabot version updates to decrease the risk of organizations automatically adopting malicious or comp...

T1195

GBHackers → Details

Help Net Security general GitHub 4d ago

GitHub delays version updates so malware gets caught first

An automated update tool watches a package registry, catches a new release the moment it publishes, and opens a pull request for your team. That is the job i...

Help Net Security → Details

BleepingComputer general GitHub 5d ago

GitHub, PyPI add time-absed defenses against supply chain attacks

GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain at...

T1195

BleepingComputer → Details

SC Media general GitHub Jul 24

GitHub to implement two-tier bug bounty program amid AI-generated report surge

GitHub is launching a two-tier bug bounty program starting July 27, 2026, in response to an increase in low-quality, AI-generated vulnerability reports.

SC Media → Details

The Hacker News general GitHub Jul 23

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure de...

The Hacker News → Details

GBHackers general GitHub Jul 23

Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers

Hackers are abusing compromised GitHub repositories and GitHub Actions workflows to build a de facto global botnet that scans and exploits web hosting server...

GBHackers → Details

Help Net Security general GitHub Jul 23

GitHub revamps bug bounty program with new VIP tier, payout changes

GitHub is changing its bug bounty program to reward higher-quality vulnerability reports and reduce low-effort submissions, including AI-generated reports. T...

Help Net Security → Details

The Hacker News general GitHub Jul 22

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000...

The Hacker News → Details

The Hacker News general GitHub Intel Jul 20

FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware

Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills ...

The Hacker News → Details

Rapid7 Blog vendor GitHub WordPress Jul 17

CVE-2026-63030: wp2shell a Critical Remote Code Execution Vulnerability in WordPress Core

Overview On July 17, 2026, a GitHub Security Advisory was published for CVE-2026-63030, a critical unauthenticated remote code execution vulnerability affect...

T1190 1 IOC

Rapid7 Blog → Details

Infosecurity Magazine general GitHub Jun 18

Fake GitHub Stars and AI Videos Mask a Crypto Clipper

A Rust crypto clipper hides behind fake GitHub stars and AI-narrated YouTube videos

Infosecurity Magazine → Details

Infosecurity Magazine general GitHub Jun 17

Serverless Phishing Kit on GitHub Targets Mexican Banks

GitBait phishing kit abuses GitHub Pages and the SheetBest API to steal Mexican banking credentials

T1566

Infosecurity Magazine → Details

Infosecurity Magazine general GitHub Jun 12

GitHub to Update npm to Thwart Software Supply Chain Attacks

NPM, part of GitHub, announced a new version of the npm package manager with several security improvements, including disabling install scripts

T1195

Infosecurity Magazine → Details

Infosecurity Magazine general GitHub May 29

AI-Generated npm Malware Leaks Its Own GitHub Token

Sloppy AI-generated npm infostealer leaked its own GitHub token, exposing the operator

Infosecurity Magazine → Details

Trail of Bits research GitHub May 22

Bringing full YAML anchor support to zizmor

In March 2026, attackers exploited a pull_request_target misconfiguration in the aquasecurity/trivy-action GitHub Action to exfiltrate organization and repos...

T1041

Trail of Bits → Details

1 2 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA