#GitHubSecurity

N-gated Hacker Newsngate
2025-05-17

😱 Look out! The Oracle VM is now a magician's hat, pulling a VM escape rabbit through a VGA device-sized hole. But don't worry, just sprinkle some GitHub magic pixie dust and your code will be safer than ever! 🧙‍♂️✨
github.com/google/security-res

2025-04-02

GitHub is shaking up code security after 39 million secrets leaked—now every team can access standalone tools backed by AI and major cloud partners. Curious how this could reshape digital protection?

thedefendopsdiaries.com/github

#githubsecurity
#softwareprotection
#secretmanagement
#cybersecuritytools
#infosec

2025-02-26
Ross A. Bakerross@rossabaker.com
2024-10-17
2024-10-10

🚨 Tax season just got trickier! 🚨 Hackers are using GitHub comment sections to bypass Secure Email Gateways and deliver malware. 😱

🔍 Cybercriminals are now hiding malicious payloads in GitHub comments, exploiting trusted platforms to sneak malware past traditional defenses.

⚠️ Stay alert: No link is completely safe, even from GitHub. Double-check before you click!

🔐 Have you ever thought GitHub comments could be used as a malware delivery tool? Let us know how your organization handles threats like this!

Read more on how to defend yourself against this sneaky campaign: guardiansofcyber.com/threats-v

#Cybersecurity #GuardiansOfCyber #MalwareAlert #SecureEmail #Phishing #GitHubSecurity #TaxSeason #InfoSec #ThreatActors #Guardians

Brian Vermeerbrianverm
2024-09-05

🔒Want to secure your GitHub repositories but don't know where to start? Check out these 10 GitHub Security Best Practices from Snyk! A must-read guide for all developers and DevOps professionals. buff.ly/2IYpaOK

2024-08-22

🚨 Critical vulnerability (CVE-2024-6800) found in GitHub Enterprise Server versions. Attackers could bypass authentication and gain admin privileges. GitHub has released patches for affected versions. Over 36,500 GHES instances exposed online, mostly in the US. Update ASAP to versions 3.13.3, 3.12.8, 3.11.14, or 3.10.16 for security.

#GitHubSecurity #CyberSecurity #SoftwareUpdate #GHES

Bleeping Computers: bleepingcomputer.com/news/secu

A flaw in Puppet Forge on GitHub could have led to a supply chain disaster matching the scope of the attack on SolarWinds. Here are the key takeaways. #SoftwareSupplyChain #RoguePuppet #PuppetForge #OpenSourceSecurity #GitHubSecurity #AdnanKhan
tinyurl.com/wzads2zk

iam-py-test :unverified:iampytest1@infosec.exchange
2024-06-26

GitHub has placed a warning on the PolyfillIO repository (github.com/polyfillpolyfill/po), and has denied access for non-logged in users. The other two repositories owned by that account are unblocked. Dismissing the warning appears to be permanent for an account.

#PolyfillIo #polyfillIoAttack #GitHubSecurity

A warning reading "This repository contains malicious content that may cause technical harms. We have decided to preserve this content for security research purposes. Please exercise CAUTION when clicking links, downloading releases, or otherwise interacting with this repository."
There are two buttons; "Discover other projects on GitHub" and "View repository".
Offscreen, there are options to block the user polyfillpolyfill and view GitHub's guidelines.
Tom's Hardware Italiatomshw
2024-01-03

🔐 Presto su GitHub: l'auth a due fattori è must-have! Non restare indietro! ⏱️

🔗 tomshw.it/business/lautenticaz

aloke majumderaloke
2023-12-05

VulnCheck reports over 9,000 GitHub repositories at risk of repojacking from username changes, plus 6,000+ due to account deletions.In total, 15,000 repositories, supporting 800,000+ Go module-versions, are exposed to this vulnerability. vulncheck.com/blog/go-repojack

Webappiawebappia
2023-07-05

OpenAI Disables ‘Browse with Bing’ on ChatGPT, Users Bypass Paywalls 

Hashtags: Summery: OpenAI has disabled the 'Browse with Bing' feature on its chatbot, ChatGPT, after users found a way to exploit it to bypass paywalls on various sites. The feature was introduced to enhance the search experience for ChatGPT Plus subscribers but had the unintended consequence of allowing users to access paywalled content. OpenAI has…

webappia.com/openai-disables-b

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst