cyber security
C2Looper v2 Uses GitHub Repositories as Full Command-and-Control Infrastructure.
C2Looper, a Rust-based backdoor likely associated with a ransomware-related threat actor.
A newer build, internally identified as version 2, replaces conventional command-and-control infrastructure with GitHub repositories used to deliver...
Cyber Security News
GitHub Expands Dependabot Malware Alerts to Detect Malicious Packages Across 8 Ecosystems
GitHub has expanded its Dependabot malware alerts beyond npm, enabling the detection of malicious dependencies across various package ecosystems, including PyPI, Maven, RubyGems, NuGet,...
cyber security
Attackers Abuse GitHub Actions Workflow to Publish Provenance-Signed npm Malware
Attackers have been observed abusing GitHub Actions workflows to distribute provenance-signed malicious npm packages, marking a significant escalation in software supply chain threats.
On...
cyber security
Operation STANDOFF Uses GitHub Redirects Across 44 Servers to Hide Multi-Malware C2 Traffic
Operation STANDOFF is a Russian‑speaking cybercriminal campaign that uses a cluster of at least 44 TimeWeb‑hosted servers that all masquerade as benign GitHub redirectors...
Cyber Security News
GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies
GitHub has introduced a default cooldown period for Dependabot version updates to decrease the risk of organizations automatically adopting malicious or compromised open-source dependencies...
Botnet
Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers
Hackers are abusing compromised GitHub repositories and GitHub Actions workflows to build a de facto global botnet that scans and exploits web hosting servers,...
Cyber Security News
Attackers Can Generate Duplicate Verified GitHub Commits Using Signature Malleability
Attackers can silently clone “Verified” GitHub commits by abusing signature malleability in Git’s commit-signing formats, creating byte‑different commits with identical content, valid signatures, and...
Cyber Security News
GitLost Vulnerability Lets Attackers Trick GitHub AI Agent Into Leaking Private Repos
A critical vulnerability known as "GitLost" has been discovered in GitHub’s newly introduced Agentic Workflows by Noma Labs. This flaw allows unauthenticated attackers to...
cyber security
Hackers Compromise GitHub Maintainer Accounts to Publish PolinRider-Infected Package Versions
A widescale escalation in the PolinRider supply‑chain campaign: threat actors have compromised GitHub maintainer accounts to publish infected package versions across multiple ecosystems.
The...
cyber security
ChocoPoC Campaign Abuses GitHub PoC Repositories to Steal Browser Credentials
A coordinated supply-chain campaign has been weaponizing GitHub proof-of-concept (PoC) repositories to compromise vulnerability researchers and penetration testers, delivering a stealthy Python Remote Access...
Cyber Security News
GitHub Actions Checkout Adds Protection Against Malicious pull_request_target Workflows
GitHub has implemented a major security enhancement in its Actions ecosystem with the release of actions/checkout v7, which aims to address a long-standing class...