Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

GitHub

20 articles

Infosecurity Magazine general GitHub Aug 18

Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed

The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher

Infosecurity Magazine → Details

GBHackers general GitHub Aug 18

C2Looper v2 Uses GitHub Repositories as Full Command-and-Control Infrastructure.

C2Looper, a Rust-based backdoor likely associated with a ransomware-related threat actor. A newer build, internally identified as version 2, replaces convent...

GBHackers → Details

The Hacker News general GitHub Intel Aug 18

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

The U.S.

The Hacker News → Details

Help Net Security general GitHub Salesforce ServiceNow Aug 16

Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems...

T1598 1 IOC

Help Net Security → Details

SC Media general GitHub Aug 13

Market for AI watermark removal tools emerges after Anthropic's Claude update

This development includes a GitHub project with over 4,500 stars, various new web tools, and existing AI detection evasion services.

SC Media → Details

BleepingComputer general GitHub Aug 13

AI 'watermark removers' flood the web. Almost none can prove they work.

Multiple 'watermark removers' have surfaced days after Anthropic began watermarking text generated by Claude, including an open source project with over 4,50...

BleepingComputer → Details

BleepingComputer general GitHub Aug 11

Mozilla updates GPG signing key for Firefox releases after exposure

Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. [.

BleepingComputer → Details

GBHackers general GitHub Linux Aug 11

Mozilla Rotates Firefox and Thunderbird GPG Signing Key After Private GitHub Exposure

Mozilla has rotated a GPG signing subkey used to authenticate release artifacts for Firefox and Thunderbird after an unencrypted copy of the previous subkey ...

GBHackers → Details

SecurityWeek general GitHub Aug 11

Mozilla Issues New Firefox GPG Key Following Exposure

The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it. The post Mozilla Issues New Firefox GPG Key ...

SecurityWeek → Details

GBHackers general GitHub Aug 10

GitHub Expands Dependabot Malware Alerts to Detect Malicious Packages Across 8 Ecosystems

GitHub has expanded its Dependabot malware alerts beyond npm, enabling the detection of malicious dependencies across various package ecosystems, including P...

1 IOC

GBHackers → Details

Security Affairs general GitHub Aug 10

A GitHub Misconfiguration Let Kimi K3 Cheat a Cybersecurity Benchmark

Kimi K3 bypassed a UK cybersecurity test by accessing GitHub, cloning the benchmark and reading its solutions instead of solving the challenge Sometimes the ...

Security Affairs → Details

Help Net Security general GitHub Aug 10

GitHub Dependabot malware alerts now cover eight ecosystems

GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.

T1598 1 IOC

Help Net Security → Details

Help Net Security general GitHub GitLab Aug 10

Chainloop: Open-source evidence store and policy engine for the software supply chain

Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeli...

T1195

Help Net Security → Details

Unit 42 research GitHub Aug 6

ChainDrop: Inside a Self-Propagating npm Worm

Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDro...

Unit 42 → Details

SANS ISC advisories GitHub Aug 5

Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)

When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle t...

T1598

SANS ISC → Details

The Hacker News general GitHub Aug 5

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to ...

T1078

The Hacker News → Details

SecurityWeek general GitHub Aug 5

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials. The post Over 400 NPM Packages Infec...

T1041 T1195

SecurityWeek → Details

CSO Online enterprise GitHub Aug 4

ChainDrop credential stealing worm infects over 400 npm packages

A self-propagating worm-like attack is hitting the npm registry, having infected 444 packages from more than a dozen publishers so far. The impact is massive...

CSO Online → Details

HackRead general GitHub Aug 4

Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages

Shai-Hulud npm worm spreads through Keyv and hundreds of packages with 2 billion monthly downloads, stealing npm, GitHub, cloud and CI credentials in real time.

HackRead → Details

Cloudflare Blog vendor GitHub Aug 4

How we built a software factory to drive Astro’s GitHub issue count to zero

By replacing manual issue verification with isolated AI subagents running in GitHub Actions, the Astro maintainers reduced open issue count by 85%. This post...

Cloudflare Blog → Details

«Previous page 1 2 3 4 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA