AI
Kimsuky Uses OpenCode AI Agent and GitHub PATs in Operation GitPower Attacks
North Korea-linked threat actor Kimsuky has expanded its Operation GitPower activity with malicious LNK shortcuts, GitHub Personal Access Token (PAT)-authenticated payload delivery, and AI-generated decoy documents linked to the...
cyber security
Malicious npm Package Steals GitHub, Cloud, and CI/CD Secrets and Spreads to Other Packages
A supply-chain compromise affecting the popular npm package @7nohe/openapi-react-query-codegen is exposing developer workstations and CI/CD runners to a credential-stealing, self-propagating payload.
On August 28,...
AWS
28,000 Exposed .git Repositories Leak Active AWS, OpenAI, Stripe and GitHub Credentials
A large-scale internet scan has uncovered 28,000 publicly accessible .git repositories exposing credentials for AWS, OpenAI, Stripe, GitHub, and other services, illustrating how a...
cyber security
C2Looper v2 Uses GitHub Repositories as Full Command-and-Control Infrastructure.
C2Looper, a Rust-based backdoor likely associated with a ransomware-related threat actor.
A newer build, internally identified as version 2, replaces conventional command-and-control infrastructure with...
Cyber Security News
GitHub Expands Dependabot Malware Alerts to Detect Malicious Packages Across 8 Ecosystems
GitHub has expanded its Dependabot malware alerts beyond npm, enabling the detection of malicious dependencies across various package ecosystems, including PyPI, Maven, RubyGems, NuGet,...
cyber security
Attackers Abuse GitHub Actions Workflow to Publish Provenance-Signed npm Malware
Attackers have been observed abusing GitHub Actions workflows to distribute provenance-signed malicious npm packages, marking a significant escalation in software supply chain threats.
On...
cyber security
Operation STANDOFF Uses GitHub Redirects Across 44 Servers to Hide Multi-Malware C2 Traffic
Operation STANDOFF is a Russian‑speaking cybercriminal campaign that uses a cluster of at least 44 TimeWeb‑hosted servers that all masquerade as benign GitHub redirectors...
Cyber Security News
GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies
GitHub has introduced a default cooldown period for Dependabot version updates to decrease the risk of organizations automatically adopting malicious or compromised open-source dependencies...
Botnet
Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers
Hackers are abusing compromised GitHub repositories and GitHub Actions workflows to build a de facto global botnet that scans and exploits web hosting servers,...
Cyber Security News
Attackers Can Generate Duplicate Verified GitHub Commits Using Signature Malleability
Attackers can silently clone “Verified” GitHub commits by abusing signature malleability in Git’s commit-signing formats, creating byte‑different commits with identical content, valid signatures, and...
Cyber Security News
GitLost Vulnerability Lets Attackers Trick GitHub AI Agent Into Leaking Private Repos
A critical vulnerability known as "GitLost" has been discovered in GitHub’s newly introduced Agentic Workflows by Noma Labs. This flaw allows unauthenticated attackers to...