GitHub App keys can still enable takeovers long after they are forgotten
GitHub allows organizations to install GitHub Apps that automate and extend certain functionality on the platform and have access to selected repositories an...
20 articles
GitHub allows organizations to install GitHub Apps that automate and extend certain functionality on the platform and have access to selected repositories an...
GitGuardian finds 474 leaked GitHub App keys still authenticating, including keys with admin access
Threat actors have compromised at least 65 public GitHub repositories in a software supply-chain campaign that abused npm trusted publishing to distribute a ...
The campaign, uncovered by LastPass and Delphos Labs, impersonates LastPass and at least 39 other companies.
An attacker copied about 170 of CrowdSec's private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on Septemb...
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information ste...
A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even ...
Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attac...
Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, acc...
OpenAI published a framework for disclosing model misalignment alongside six reports describing problematic behavior. The post OpenAI Says Its Models Searche...
Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is al...
Two critical ArangoDB vulnerabilities can allow unauthenticated attackers to access protected database APIs and, after obtaining valid database access, escal...
MapLibre GL JS users are advised to upgrade their software following the disclosure of an XSS vulnerability, identified as CVE-2026-85061 and documented in G...
North Korea-linked threat actor Kimsuky has expanded its Operation GitPower activity with malicious LNK shortcuts, GitHub Personal Access Token (PAT)-authent...
A supply-chain compromise affecting the popular npm package @7nohe/openapi-react-query-codegen is exposing developer workstations and CI/CD runners to a cred...
Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification. ...
Over 50,000 Stripe API keys have been exposed across public code repositories, GitHub Actions logs, and misconfigured web servers, demonstrating the immediat...
An autonomous AI security agent developed by cloud security firm Wiz identified and exploited a critical vulnerability in Snowflake’s GitHub Actions pipeline...
Over 50,000 exposed Stripe API keys show how leaked secrets can enable fraud, data access and account abuse within hours. Ransomnews researchers have documen...