Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

GitHub

20 articles

GBHackers Vulnerability Disclosure GitHub May 23

Hackers Compromise Laravel-Lang Packages via 700 GitHub Repos

A sophisticated and active supply chain attack has struck the Laravel-Lang open-source organization, compromising over 700 historical package versions across...

T1190 T1195

GBHackers →

SC Media General GitHub May 22

TVs, Old York, Flipper One, Ubiquity, Underminr, CISOs, GitHub, Josh Marpet... - SWN #583

SC Media →

HackRead Supply Chain GitHub May 22

5,561 GitHub Repositories Hit by Megalodon Supply Chain Attack in Six Hours

SafeDep uncovered the Megalodon attack targeting 5,561 GitHub repositories with malicious CI workflows and cloud credential theft.

T1078 T1195

HackRead →

The Hacker News Campaigns GitHub May 22

Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows

Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561 GitHub reposit...

T1041

The Hacker News →

Trail of Bits Malware GitHub May 22

We hardened zizmor's GitHub Actions static analyzer

In March 2026, attackers exploited a pull_request_target misconfiguration in the aquasecurity/trivy-action GitHub Action to exfiltrate organization and repos...

T1041

Trail of Bits →

SecurityWeek Supply Chain GitHub May 22

Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack

Hackers accessed Grafana’s GitHub repositories after a token compromised in the TanStack attack was not rotated. The post Grafana Says Codebase and Other Dat...

T1041 T1195

SecurityWeek →

GBHackers Campaigns GitHub May 22

Megalodon Malware Rapidly Infects Over 5,500 GitHub Repositories

A newly identified malware campaign dubbed “Megalodon” has compromised more than 5,500 GitHub repositories, raising serious concerns about the security of op...

GBHackers →

SC Media Supply Chain GitHub May 21

FCC, Github, MiniShai-hulud, Stated of Supply Chain, Itron, CRA, NIS2, and more!! - PSW #927

SC Media →

SC Media Data Breach GitHub May 21

Senator urges classified briefing after CISA data leak on GitHub

A GitHub leak exposed CISA credentials, sparking concerns over secrets management and leadership.

SC Media →

Infosecurity Magazine Data Breach GitHub May 21

GitHub Breach Traced to Malicious 'Nx Console' VS Code Extension

A threat actor compromised an Nx developer and posed as a legitimate maintainer to publish a malicious extension on Visual Studio Marketplace

Infosecurity Magazine →

Help Net Security Data Breach GitHub May 21

GitHub, Grafana Labs breaches traced back to TanStack supply chain compromise

GitHub CISO Alexis Wales has named the malicious VS Code extension behind the breach they suffered at the hands of the threat group TeamPCP: Nx Console, a po...

T1041 T1195

Help Net Security →

BleepingComputer Data Breach GitHub May 21

GitHub links repo breach to TanStack npm supply-chain attack

GitHub says the hackers who breached 3,800 internal repositories gained access via a malicious version of the Nx Console VS Code extension, compromised in la...

BleepingComputer →

SC Media Campaigns GitHub May 20

New Mini Shai-Hulud attack targets npm ecosystem

Mini Shai-Hulud campaign hits 323 npm packages, GitHub Actions and VS Code tools.

SC Media →

BleepingComputer Data Breach GitHub May 20

Grafana breach caused by missed token rotation after TanStack attack

The Grafana data breach was caused by a single GitHub workflow token that slipped through the rotation process following the TanStack npm supply-chain attack...

BleepingComputer →

HackRead Data Breach GitHub May 20

GitHub Breach: TeamPCP Steals 3,800 Repositories via VS Code Extension

GitHub Breach: TeamPCP stole 3,800 internal repositories through a malicious VS Code extension and is now selling the data online for $95,000.

HackRead →

GBHackers Data Breach GitHub May 20

Grafana GitHub Security Incident Reportedly Connected to TanStack npm Ransomware

Grafana Labs has disclosed a targeted GitHub security incident linked to the ongoing TanStack npm supply chain ransomware campaign, raising concerns about so...

GBHackers →

The Record Data Breach GitHub May 20

GitHub confirms being hacked by TeamPCP, says customer data unaffected

Github, which hosts code for more than 100 million developers worldwide, confirmed the breach on social media after TeamPCP advertised stolen source code on ...

The Record →

The Record Data Breach GitHub May 20

Senator presses CISA for answers about alleged GitHub repository leak

U.S.

The Record →

Infosecurity Magazine Data Breach GitHub May 20

GitHub Confirms Breach of Internal Repositories Via Malicious VS Code Extension

The prolific threat group TeamPCP has claimed a hack into GitHub’s internal repositories

Infosecurity Magazine →

SecurityWeek General GitHub May 20

GitHub Confirms Hack Impacting 3,800 Internal Repositories

The TeamPCP hacking group accessed the repositories after a GitHub employee installed a poisoned VS Code extension. The post GitHub Confirms Hack Impacting 3...

SecurityWeek →

«Previous page 1 2 3 4 5 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA