#githubsecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #githubsecurity, aggregated by home.social.
-
🎉 Oh, look! Another riveting Windows update destined to "revolutionize" our lives by granting system user access to everyone and their grandmother. 🚀 And let's not forget about the obligatory GitHub plug—because who doesn't love sifting through endless repos to patch Microsoft's idea of security? 🙄
https://github.com/Nightmare-Eclipse/RedSun #WindowsUpdate #GitHubSecurity #UserAccess #TechHumor #MicrosoftPatch #HackerNews #ngated -
Researchers have documented a campaign abusing GitHub repositories themed as OSINT tools, GPT utilities, and developer resources to deliver PyStoreRAT, a modular, multi-stage remote access trojan.
The operation leverages delayed malicious commits, minimal loader stubs, reputation manipulation, and HTA-based execution to reduce early detection. In parallel, a separate RAT campaign demonstrates region- and language-aware targeting logic.
These cases underscore evolving tradecraft around trust abuse and script-based implants.
How are you adapting repository vetting and execution controls in your environment?Source: https://thehackernews.com/2025/12/fake-osint-and-gpt-utility-github-repos.html
Engage in the discussion and follow TechNadu for measured infosec reporting.
#InfoSec #ThreatIntel #MalwareAnalysis #GitHubSecurity #OpenSourceRisk #TechNadu
-
Researchers have documented a campaign abusing GitHub repositories themed as OSINT tools, GPT utilities, and developer resources to deliver PyStoreRAT, a modular, multi-stage remote access trojan.
The operation leverages delayed malicious commits, minimal loader stubs, reputation manipulation, and HTA-based execution to reduce early detection. In parallel, a separate RAT campaign demonstrates region- and language-aware targeting logic.
These cases underscore evolving tradecraft around trust abuse and script-based implants.
How are you adapting repository vetting and execution controls in your environment?Source: https://thehackernews.com/2025/12/fake-osint-and-gpt-utility-github-repos.html
Engage in the discussion and follow TechNadu for measured infosec reporting.
#InfoSec #ThreatIntel #MalwareAnalysis #GitHubSecurity #OpenSourceRisk #TechNadu
-
Researchers have documented a campaign abusing GitHub repositories themed as OSINT tools, GPT utilities, and developer resources to deliver PyStoreRAT, a modular, multi-stage remote access trojan.
The operation leverages delayed malicious commits, minimal loader stubs, reputation manipulation, and HTA-based execution to reduce early detection. In parallel, a separate RAT campaign demonstrates region- and language-aware targeting logic.
These cases underscore evolving tradecraft around trust abuse and script-based implants.
How are you adapting repository vetting and execution controls in your environment?Source: https://thehackernews.com/2025/12/fake-osint-and-gpt-utility-github-repos.html
Engage in the discussion and follow TechNadu for measured infosec reporting.
#InfoSec #ThreatIntel #MalwareAnalysis #GitHubSecurity #OpenSourceRisk #TechNadu
-
Researchers have documented a campaign abusing GitHub repositories themed as OSINT tools, GPT utilities, and developer resources to deliver PyStoreRAT, a modular, multi-stage remote access trojan.
The operation leverages delayed malicious commits, minimal loader stubs, reputation manipulation, and HTA-based execution to reduce early detection. In parallel, a separate RAT campaign demonstrates region- and language-aware targeting logic.
These cases underscore evolving tradecraft around trust abuse and script-based implants.
How are you adapting repository vetting and execution controls in your environment?Source: https://thehackernews.com/2025/12/fake-osint-and-gpt-utility-github-repos.html
Engage in the discussion and follow TechNadu for measured infosec reporting.
#InfoSec #ThreatIntel #MalwareAnalysis #GitHubSecurity #OpenSourceRisk #TechNadu
-
Researchers have documented a campaign abusing GitHub repositories themed as OSINT tools, GPT utilities, and developer resources to deliver PyStoreRAT, a modular, multi-stage remote access trojan.
The operation leverages delayed malicious commits, minimal loader stubs, reputation manipulation, and HTA-based execution to reduce early detection. In parallel, a separate RAT campaign demonstrates region- and language-aware targeting logic.
These cases underscore evolving tradecraft around trust abuse and script-based implants.
How are you adapting repository vetting and execution controls in your environment?Source: https://thehackernews.com/2025/12/fake-osint-and-gpt-utility-github-repos.html
Engage in the discussion and follow TechNadu for measured infosec reporting.
#InfoSec #ThreatIntel #MalwareAnalysis #GitHubSecurity #OpenSourceRisk #TechNadu
-
GitHub notifications trusted you, right? Now imagine them doubling as a gateway for a Y Combinator scam that stole crypto. One subtle typo in a domain and hackers had developers in their sights. Stay vigilant—this one’s a wake-up call!
#githubsecurity
#phishing
#cryptotheft
#socialengineering
#infosec
#web3security
#zerotrust
#cybersecurity
#domainspoofing -
GitHub notifications trusted you, right? Now imagine them doubling as a gateway for a Y Combinator scam that stole crypto. One subtle typo in a domain and hackers had developers in their sights. Stay vigilant—this one’s a wake-up call!
#githubsecurity
#phishing
#cryptotheft
#socialengineering
#infosec
#web3security
#zerotrust
#cybersecurity
#domainspoofing -
GitHub notifications trusted you, right? Now imagine them doubling as a gateway for a Y Combinator scam that stole crypto. One subtle typo in a domain and hackers had developers in their sights. Stay vigilant—this one’s a wake-up call!
#githubsecurity
#phishing
#cryptotheft
#socialengineering
#infosec
#web3security
#zerotrust
#cybersecurity
#domainspoofing -
🎉 Breaking news: Typo alert! Some genius decided to check if misspelling "ghcr.io" as "ghrc.io" would lead to a secret Nginx rave 🕺—only to discover it's a phishing scam instead. Who knew a single letter could compromise your GitHub creds faster than you can say "oops"? 🤦♂️
https://bmitch.net/blog/2025-08-22-ghrc-appears-malicious/ #TypoAlert #PhishingScam #GitHubSecurity #NginxRave #CyberSecurity #HackerNews #ngated -
🎉 Breaking news: Typo alert! Some genius decided to check if misspelling "ghcr.io" as "ghrc.io" would lead to a secret Nginx rave 🕺—only to discover it's a phishing scam instead. Who knew a single letter could compromise your GitHub creds faster than you can say "oops"? 🤦♂️
https://bmitch.net/blog/2025-08-22-ghrc-appears-malicious/ #TypoAlert #PhishingScam #GitHubSecurity #NginxRave #CyberSecurity #HackerNews #ngated -
🎉 Breaking news: Typo alert! Some genius decided to check if misspelling "ghcr.io" as "ghrc.io" would lead to a secret Nginx rave 🕺—only to discover it's a phishing scam instead. Who knew a single letter could compromise your GitHub creds faster than you can say "oops"? 🤦♂️
https://bmitch.net/blog/2025-08-22-ghrc-appears-malicious/ #TypoAlert #PhishingScam #GitHubSecurity #NginxRave #CyberSecurity #HackerNews #ngated -
🎉 Breaking news: Typo alert! Some genius decided to check if misspelling "ghcr.io" as "ghrc.io" would lead to a secret Nginx rave 🕺—only to discover it's a phishing scam instead. Who knew a single letter could compromise your GitHub creds faster than you can say "oops"? 🤦♂️
https://bmitch.net/blog/2025-08-22-ghrc-appears-malicious/ #TypoAlert #PhishingScam #GitHubSecurity #NginxRave #CyberSecurity #HackerNews #ngated -
The Amazon Q AI Hack: A Wake-Up Call for Developer Tool Security
Nearly 1 million developers unknowingly downloaded malicious code—and it took 6 days before anyone noticed.
In this episode of Cyberside Chats, @sherridavidoff and @MDurrin dive into the Amazon Q AI Hack, a stark reminder of how vulnerable our software development tools truly are. From GitHub misconfigurations to supply chain breaches, we’ll explore:
🔹 How a single GitHub token compromise allowed a hacker to inject destructive AI prompts
🔹 Why popular AI tools like Copilot, Gemini, and Q are not as safe as you think
🔹 Supply chain attack lessons from SolarWinds, XZ Utils, and NotPetya
🔹 Best practices to secure your build pipelines and vet third-party developers🎥 Watch the video: https://youtu.be/qHQ4jdZ7mwI
🎧 Listen to the podcast: https://www.chatcyberside.com/e/unmasking-the-amazon-q-ai-hack-the-hidden-dangers-in-software-development#Cybersecurity #SupplyChainSecurity #AItools #DevSecOps #AmazonQHack #GitHubSecurity #Infosec #CybersideChats #LMGSecurity
-
The Amazon Q AI Hack: A Wake-Up Call for Developer Tool Security
Nearly 1 million developers unknowingly downloaded malicious code—and it took 6 days before anyone noticed.
In this episode of Cyberside Chats, @sherridavidoff and @MDurrin dive into the Amazon Q AI Hack, a stark reminder of how vulnerable our software development tools truly are. From GitHub misconfigurations to supply chain breaches, we’ll explore:
🔹 How a single GitHub token compromise allowed a hacker to inject destructive AI prompts
🔹 Why popular AI tools like Copilot, Gemini, and Q are not as safe as you think
🔹 Supply chain attack lessons from SolarWinds, XZ Utils, and NotPetya
🔹 Best practices to secure your build pipelines and vet third-party developers🎥 Watch the video: https://youtu.be/qHQ4jdZ7mwI
🎧 Listen to the podcast: https://www.chatcyberside.com/e/unmasking-the-amazon-q-ai-hack-the-hidden-dangers-in-software-development#Cybersecurity #SupplyChainSecurity #AItools #DevSecOps #AmazonQHack #GitHubSecurity #Infosec #CybersideChats #LMGSecurity
-
The Amazon Q AI Hack: A Wake-Up Call for Developer Tool Security
Nearly 1 million developers unknowingly downloaded malicious code—and it took 6 days before anyone noticed.
In this episode of Cyberside Chats, @sherridavidoff and @MDurrin dive into the Amazon Q AI Hack, a stark reminder of how vulnerable our software development tools truly are. From GitHub misconfigurations to supply chain breaches, we’ll explore:
🔹 How a single GitHub token compromise allowed a hacker to inject destructive AI prompts
🔹 Why popular AI tools like Copilot, Gemini, and Q are not as safe as you think
🔹 Supply chain attack lessons from SolarWinds, XZ Utils, and NotPetya
🔹 Best practices to secure your build pipelines and vet third-party developers🎥 Watch the video: https://youtu.be/qHQ4jdZ7mwI
🎧 Listen to the podcast: https://www.chatcyberside.com/e/unmasking-the-amazon-q-ai-hack-the-hidden-dangers-in-software-development#Cybersecurity #SupplyChainSecurity #AItools #DevSecOps #AmazonQHack #GitHubSecurity #Infosec #CybersideChats #LMGSecurity
-
GitHub's repo network can expose deleted or private commits. Learn how forks, SHAs, and metadata can leak your secrets even after cleanup. https://hackernoon.com/why-github-commits-arent-as-private-as-you-think #githubsecurity
-
😱 Look out! The Oracle VM #VirtualBox is now a magician's hat, pulling a VM escape rabbit through a VGA device-sized hole. But don't worry, just sprinkle some GitHub magic pixie dust and your code will be safer than ever! 🧙♂️✨
https://github.com/google/security-research/security/advisories/GHSA-qx2m-rcpc-v43v #OracleVM #VMescape #GitHubSecurity #MagicCoding #HackerNews #ngated -
😱 Look out! The Oracle VM #VirtualBox is now a magician's hat, pulling a VM escape rabbit through a VGA device-sized hole. But don't worry, just sprinkle some GitHub magic pixie dust and your code will be safer than ever! 🧙♂️✨
https://github.com/google/security-research/security/advisories/GHSA-qx2m-rcpc-v43v #OracleVM #VMescape #GitHubSecurity #MagicCoding #HackerNews #ngated -
😱 Look out! The Oracle VM #VirtualBox is now a magician's hat, pulling a VM escape rabbit through a VGA device-sized hole. But don't worry, just sprinkle some GitHub magic pixie dust and your code will be safer than ever! 🧙♂️✨
https://github.com/google/security-research/security/advisories/GHSA-qx2m-rcpc-v43v #OracleVM #VMescape #GitHubSecurity #MagicCoding #HackerNews #ngated -
😱 Look out! The Oracle VM #VirtualBox is now a magician's hat, pulling a VM escape rabbit through a VGA device-sized hole. But don't worry, just sprinkle some GitHub magic pixie dust and your code will be safer than ever! 🧙♂️✨
https://github.com/google/security-research/security/advisories/GHSA-qx2m-rcpc-v43v #OracleVM #VMescape #GitHubSecurity #MagicCoding #HackerNews #ngated -
GitHub is shaking up code security after 39 million secrets leaked—now every team can access standalone tools backed by AI and major cloud partners. Curious how this could reshape digital protection?
https://thedefendopsdiaries.com/githubs-security-tools-expansion-a-new-era-in-software-protection/
#githubsecurity
#softwareprotection
#secretmanagement
#cybersecuritytools
#infosec -
GitHub is shaking up code security after 39 million secrets leaked—now every team can access standalone tools backed by AI and major cloud partners. Curious how this could reshape digital protection?
https://thedefendopsdiaries.com/githubs-security-tools-expansion-a-new-era-in-software-protection/
#githubsecurity
#softwareprotection
#secretmanagement
#cybersecuritytools
#infosec -
Malware Campaign Exploits GitHub, Infecting Nearly One Million Devices
#Cybersecurity #GitHub #GitHubSecurity #Malware #CyberCrime #MicrosoftSecurity #OpenSourceSecurity #CyberAttacks #GitHubMalware
-
CW: GitHub Security and too many ways to sort versions
We had a vulnerable dependency affecting versions `< 9.4.54` and patched it with `9.4.54.v20240208`. The CVE is declared in the Maven ecosystem, and while this version is correct according to Maven's rules [^1], it does not satisfy the predicate according to SemVer [^2], and the vulnerability scan continues to fire.
[^1]: https://maven.apache.org/ref/3.9.9/maven-artifact/apidocs/org/apache/maven/artifact/versioning/ComparableVersion.html
[^2] : https://semver.org/#spec-item-11 -
🔒Want to secure your GitHub repositories but don't know where to start? Check out these 10 GitHub Security Best Practices from Snyk! A must-read guide for all developers and DevOps professionals. https://buff.ly/2IYpaOK #DevSecOps #GitHubSecurity
-
GitHub Vulnerability “ArtiPACKED” Trigger RCE Exploit to Hack Repositories https://cybersecuritynews.com/github-vulnerability/ #CyberSecurityResearch #InformationSecurity #remotecodeexecution #CI/CDPipelines #GitHubSecurity #Vulnerability
-
GitHub has placed a warning on the PolyfillIO repository (https://github.com/polyfillpolyfill/polyfill-service), and has denied access for non-logged in users. The other two repositories owned by that account are unblocked. Dismissing the warning appears to be permanent for an account.