Saturday, September 12, 2026

GitHub

Kimsuky Uses OpenCode AI Agent and GitHub PATs in Operation GitPower Attacks

North Korea-linked threat actor Kimsuky has expanded its Operation GitPower activity with malicious LNK shortcuts, GitHub Personal Access Token (PAT)-authenticated payload delivery, and AI-generated decoy documents linked to the...

Malicious npm Package Steals GitHub, Cloud, and CI/CD Secrets and Spreads to Other Packages

A supply-chain compromise affecting the popular npm package @7nohe/openapi-react-query-codegen is exposing developer workstations and CI/CD runners to a credential-stealing, self-propagating payload. On August 28,...

28,000 Exposed .git Repositories Leak Active AWS, OpenAI, Stripe and GitHub Credentials

A large-scale internet scan has uncovered 28,000 publicly accessible .git repositories exposing credentials for AWS, OpenAI, Stripe, GitHub, and other services, illustrating how a...

C2Looper v2 Uses GitHub Repositories as Full Command-and-Control Infrastructure.

C2Looper, a Rust-based backdoor likely associated with a ransomware-related threat actor. A newer build, internally identified as version 2, replaces conventional command-and-control infrastructure with...

GitHub Expands Dependabot Malware Alerts to Detect Malicious Packages Across 8 Ecosystems

GitHub has expanded its Dependabot malware alerts beyond npm, enabling the detection of malicious dependencies across various package ecosystems, including PyPI, Maven, RubyGems, NuGet,...

Attackers Abuse GitHub Actions Workflow to Publish Provenance-Signed npm Malware

Attackers have been observed abusing GitHub Actions workflows to distribute provenance-signed malicious npm packages, marking a significant escalation in software supply chain threats. On...

Operation STANDOFF Uses GitHub Redirects Across 44 Servers to Hide Multi-Malware C2 Traffic

Operation STANDOFF is a Russian‑speaking cybercriminal campaign that uses a cluster of at least 44 TimeWeb‑hosted servers that all masquerade as benign GitHub redirectors...

GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies

GitHub has introduced a default cooldown period for Dependabot version updates to decrease the risk of organizations automatically adopting malicious or compromised open-source dependencies...

Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers

Hackers are abusing compromised GitHub repositories and GitHub Actions workflows to build a de facto global botnet that scans and exploits web hosting servers,...

Attackers Can Generate Duplicate Verified GitHub Commits Using Signature Malleability

Attackers can silently clone “Verified” GitHub commits by abusing signature malleability in Git’s commit-signing formats, creating byte‑different commits with identical content, valid signatures, and...

GitLost Vulnerability Lets Attackers Trick GitHub AI Agent Into Leaking Private Repos

A critical vulnerability known as "GitLost" has been discovered in GitHub’s newly introduced Agentic Workflows by Noma Labs. This flaw allows unauthenticated attackers to...