Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

GitHub

20 articles

GBHackers general GitHub 15h ago

Hackers Compromise 65 GitHub Repositories and Poison npm Package With Hidden Backdoor

Threat actors have compromised at least 65 public GitHub repositories in a software supply-chain campaign that abused npm trusted publishing to distribute a ...

GBHackers → Details

SC Media general GitHub 1d ago

New Rapuncel infostealer campaign uses fake GitHub repos to disable antivirus

The campaign, uncovered by LastPass and Delphos Labs, impersonates LastPass and at least 39 other companies.

T1562

SC Media → Details

The Hacker News general GitHub 3d ago

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on Septemb...

T1195

The Hacker News → Details

BleepingComputer general GitHub 4d ago

Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer

An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information ste...

BleepingComputer → Details

The Hacker News general GitHub 4d ago

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even ...

The Hacker News → Details

Help Net Security general GitHub 4d ago

Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched

Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attac...

Help Net Security → Details

Help Net Security general GitHub 4d ago

Hardcoded MCP credentials found in public GitHub files

Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, acc...

Help Net Security → Details

SecurityWeek general GitHub 5d ago

OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training

OpenAI published a framework for disclosing model misalignment alongside six reports describing problematic behavior. The post OpenAI Says Its Models Searche...

SecurityWeek → Details

Kaspersky Securelist research GitHub Docker 6d ago

NightEagle targets Russian companies

Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is al...

Kaspersky Securelist → Details

GBHackers general GitHub Sep 9

Critical ArangoDB Bugs Expose Entire Databases and Enable Remote Code Execution as Root

Two critical ArangoDB vulnerabilities can allow unauthenticated attackers to access protected database APIs and, after obtaining valid database access, escal...

T1190

GBHackers → Details

GBHackers general GitHub Sep 9

Critical MapLibre GL JS Vulnerability Enables Zero-Click XSS Attacks

MapLibre GL JS users are advised to upgrade their software following the disclosure of an XSS vulnerability, identified as CVE-2026-85061 and documented in G...

1 IOC

GBHackers → Details

GBHackers general GitHub Sep 7

Kimsuky Uses OpenCode AI Agent and GitHub PATs in Operation GitPower Attacks

North Korea-linked threat actor Kimsuky has expanded its Operation GitPower activity with malicious LNK shortcuts, GitHub Personal Access Token (PAT)-authent...

GBHackers → Details

GBHackers general GitHub Sep 1

Malicious npm Package Steals GitHub, Cloud, and CI/CD Secrets and Spreads to Other Packages

A supply-chain compromise affecting the popular npm package @7nohe/openapi-react-query-codegen is exposing developer workstations and CI/CD runners to a cred...

GBHackers → Details

SecurityWeek general GitHub Linux Aug 21

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug

Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification. ...

T1498

SecurityWeek → Details

SC Media general GitHub Aug 21

Over 50,000 Stripe API keys exposed, highlighting fraud risks

Over 50,000 Stripe API keys have been exposed across public code repositories, GitHub Actions logs, and misconfigured web servers, demonstrating the immediat...

SC Media → Details

CSO Online enterprise GitHub Aug 19

Snowflake flaw slips past AI checks, gets exploited by another AI

An autonomous AI security agent developed by cloud security firm Wiz identified and exploited a critical vulnerability in Snowflake’s GitHub Actions pipeline...

CSO Online → Details

Security Affairs general GitHub Aug 19

50,000 Stripe Secrets Leaked in Public Code

Over 50,000 exposed Stripe API keys show how leaked secrets can enable fraud, data access and account abuse within hours. Ransomnews researchers have documen...

Security Affairs → Details

SC Media general GitHub Aug 18

Secrets, Red Agent, GitHub, evoooo1bot, DecryptAds, Copilot, Aaran Leyland, and More - SWN #608

SC Media → Details

Infosecurity Magazine general GitHub Aug 18

Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed

The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher

Infosecurity Magazine → Details

GBHackers general GitHub Aug 18

C2Looper v2 Uses GitHub Repositories as Full Command-and-Control Infrastructure.

C2Looper, a Rust-based backdoor likely associated with a ransomware-related threat actor. A newer build, internally identified as version 2, replaces convent...

GBHackers → Details

1 2 3 4 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA