Saturday, August 22, 2026

GitHub

C2Looper v2 Uses GitHub Repositories as Full Command-and-Control Infrastructure.

C2Looper, a Rust-based backdoor likely associated with a ransomware-related threat actor. A newer build, internally identified as version 2, replaces conventional command-and-control infrastructure with GitHub repositories used to deliver...

GitHub Expands Dependabot Malware Alerts to Detect Malicious Packages Across 8 Ecosystems

GitHub has expanded its Dependabot malware alerts beyond npm, enabling the detection of malicious dependencies across various package ecosystems, including PyPI, Maven, RubyGems, NuGet,...

Attackers Abuse GitHub Actions Workflow to Publish Provenance-Signed npm Malware

Attackers have been observed abusing GitHub Actions workflows to distribute provenance-signed malicious npm packages, marking a significant escalation in software supply chain threats. On...

Operation STANDOFF Uses GitHub Redirects Across 44 Servers to Hide Multi-Malware C2 Traffic

Operation STANDOFF is a Russian‑speaking cybercriminal campaign that uses a cluster of at least 44 TimeWeb‑hosted servers that all masquerade as benign GitHub redirectors...

GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies

GitHub has introduced a default cooldown period for Dependabot version updates to decrease the risk of organizations automatically adopting malicious or compromised open-source dependencies...

Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers

Hackers are abusing compromised GitHub repositories and GitHub Actions workflows to build a de facto global botnet that scans and exploits web hosting servers,...

Attackers Can Generate Duplicate Verified GitHub Commits Using Signature Malleability

Attackers can silently clone “Verified” GitHub commits by abusing signature malleability in Git’s commit-signing formats, creating byte‑different commits with identical content, valid signatures, and...

GitLost Vulnerability Lets Attackers Trick GitHub AI Agent Into Leaking Private Repos

A critical vulnerability known as "GitLost" has been discovered in GitHub’s newly introduced Agentic Workflows by Noma Labs. This flaw allows unauthenticated attackers to...

Hackers Compromise GitHub Maintainer Accounts to Publish PolinRider-Infected Package Versions

A widescale escalation in the PolinRider supply‑chain campaign: threat actors have compromised GitHub maintainer accounts to publish infected package versions across multiple ecosystems. The...

ChocoPoC Campaign Abuses GitHub PoC Repositories to Steal Browser Credentials

A coordinated supply-chain campaign has been weaponizing GitHub proof-of-concept (PoC) repositories to compromise vulnerability researchers and penetration testers, delivering a stealthy Python Remote Access...

GitHub Actions Checkout Adds Protection Against Malicious pull_request_target Workflows

GitHub has implemented a major security enhancement in its Actions ecosystem with the release of actions/checkout v7, which aims to address a long-standing class...