Stay Informed

Cybersecurity News

Home / News

Clear

Quick searches: Linux Windows Microsoft 365 AWS OVH VMware WordPress Fortinet Citrix VPN

47 result(s) for "GitHub" — best match first.

Latest headlines from security outlets

Collected every two hours from specialised publications — each link leads to the original article.

The Hacker News
The Hacker News Breaches & leaks
Researchers Uncover New Drokbk Malware that Uses GitHub as a Dead Drop Resolver

The subgroup of an Iranian nation-state group known asNemesis Kittenhas been attributed as behind a previously undocumented custom malware dubbed Drokbk that u…

GitHub

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks
Dropbox Confirms Serious Security Breach in which Hackers Stole code from 130 GitHub Repositories

Dropbox has revealed details of a phishing attack to which it fell victim. In the attack, a threat actor was able to steal code from the company after gatherin…

GitHub

Latest Hacking News
Latest Hacking News Breaches & leaks
GitHub Shares Details About The Stolen OAuth User Tokens Breach

Earlier this month, GitHub suffered a massive security breach affecting numerous users’ accounts. The breach…GitHub Shares Details About The Stolen OAuth User …

GitHub

The Hacker News
The Hacker News Breaches & leaks
OpenAI Patches ChatGPT Data Exfiltration Flaw and Codex GitHub Token Vulnerability

A previously unknown vulnerability in OpenAI ChatGPT allowed sensitive conversation data to be exfiltrated without user knowledge or consent, according to new …

GitHub

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories Breaches & leaks
Fedora 41: golang-github-openprinting-ipp-usb Critical Memory Leak Alert

Rebuild with the latest golang in repos

Linux GitHub

The Hacker News
The Hacker News Breaches & leaks
Malicious Nx Packages in ‘s1ngularity’ Attack Leaked 2,349 GitHub, Cloud, and AI Credentials

The maintainers of the nx build system have alerted users to a supply chain attack that allowed attackers to publish malicious versions of the popular npm pack…

GitHub

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories Breaches & leaks
Debian LTS: DLA-3322-1: golang-github-opencontainers-selinux

runc, as used in Docker and other products, allows AppArmor and SELinux restriction bypass, and thus a malicious Docker image could breach isolation.

Linux Docker GitHub

LinuxSecurity - Security Articles
LinuxSecurity - Security Articles Breaches & leaks
Compromised VS Code Extension Puts Linux Development Pipelines at Risk

The compromise of Nx Console shows how much infrastructure now sits behind a single developer account. GitHub repositories, CI/CD pipelines, container build sy…

Linux Docker Kubernetes

The Hacker News
The Hacker News Breaches & leaks
OpenAI Codex Authentication Tokens Stolen in codexui-android npm Supply Chain Attack

Cybersecurity researchers have disclosed details of a new malicious supply chain campaign that's targeting developers using OpenAI Codex through a legitimate-l…

GitHub Android

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories Breaches & leaks
Fedora 44 libexif Update 0.6.26 Fixes DoS Info Leak FEDORA-2026-fd361a6f7f

Update to 0.6.26, fixing several CVEs https://github.com/libexif/libexif/releases/tag/v0.6.26

Linux GitHub

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories Breaches & leaks
Fedora 43 libexif Medium Denial of Service Info Leak Vulnerability

Update to 0.6.26, fixing several CVEs https://github.com/libexif/libexif/releases/tag/v0.6.26

Linux GitHub

The Hacker News
The Hacker News Breaches & leaks
OpenAI Revokes macOS App Certificate After Malicious Axios Supply Chain Incident

OpenAI revealed a GitHub Actions workflow used to sign its macOS apps led to the download of the malicious Axios library on March 31, but noted that no user da…

GitHub Apple

The Hacker News
The Hacker News Breaches & leaks
UNC6426 Exploits nx npm Supply-Chain Attack to Gain AWS Admin Access in 72 Hours

A threat actor known as UNC6426 leveraged keys stolen following the supply chain compromise of the nx npm package last year to completely breach a victim's clo…

AWS GitHub

The Hacker News
The Hacker News Breaches & leaks
Malicious Go Crypto Module Steals Passwords, Deploys Rekoobe Backdoor

Cybersecurity researchers have disclosed details of a malicious Go module that's designed to harvest passwords, create persistent access via SSH, and deliver a…

Linux GitHub

The Hacker News
The Hacker News Breaches & leaks
Traditional Security Frameworks Leave Organizations Exposed to AI-Specific Attack Vectors

In December 2024, the popular Ultralytics AI library was compromised, installing malicious code that hijacked system resources for cryptocurrency mining. In Au…

GitHub

The Hacker News
The Hacker News Breaches & leaks
Malware Injected into 6 npm Packages After Maintainer Tokens Stolen in Phishing Attack

Cybersecurity researchers have alerted to a supply chain attack that has targeted popular npm packages via a phishing campaign designed to steal the project ma…

GitHub

The Hacker News
The Hacker News Breaches & leaks
Malware Injected into 5 npm Packages After Maintainer Tokens Stolen in Phishing Attack

Cybersecurity researchers have alerted to a supply chain attack that has targeted popular npm packages via a phishing campaign designed to steal the project ma…

GitHub

The Hacker News
The Hacker News Breaches & leaks
Malware Injected into 7 npm Packages After Maintainer Tokens Stolen in Phishing Attack

Cybersecurity researchers have alerted to a supply chain attack that has targeted popular npm packages via a phishing campaign designed to steal the project ma…

GitHub

The Hacker News
The Hacker News Breaches & leaks
Malicious Pull Request Targets 6,000+ Developers via Vulnerable Ethcode VS Code Extension

Cybersecurity researchers have flagged a supply chain attack targeting a Microsoft Visual Studio Code (VS Code) extension called Ethcode that has been installe…

GitHub

The Hacker News
The Hacker News Breaches & leaks
FireScam Android Malware Poses as Telegram Premium to Steal Data and Control Devices

An Android information stealing malware named FireScam has been found masquerading as a premium version of the Telegram messaging app to steal data and maintai…

GitHub Android

The Hacker News
The Hacker News Breaches & leaks
Open Source Ransomware Toolkit Cryptonite Turns Into Accidental Wiper Malware

A version of an open source ransomware toolkit calledCryptonitehas been observed in the wild with wiper capabilities due to its "weak architecture and programm…

GitHub

LinuxSecurity - Security Advisories
LinuxSecurity - Security Advisories Breaches & leaks
Mageia 2022-0055: firejail security upda

private-cwd leaks access to the entire filesystem References: - https://bugs.mageia.org/show_bug.cgi?id=30007 - https://github.com/netblue30/firejail/issues/47…

GitHub

The Hacker News
The Hacker News Breaches & leaks
Researchers Detail Modus Operandi of ShinyHunters Cyber Crime Group

ShinyHunters, a notorious cybercriminal underground group that's been on a data breach spree since last year, has been observed searching companies' GitHub rep…

GitHub