#githubsecurity — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #githubsecurity, aggregated by home.social.
-
Oh, GitHub's security team! 😂 With billions in their pocket and AI at their fingertips, they still can't find a digital virus in a haystack. Who knew the best malware detection tool was...the search bar? 🔍💰
https://orchidfiles.com/github-security-team/ #GitHubSecurity #AIDetection #MalwareSearch #DigitalVirus #HaystackHacks #HackerNews #ngated -
Oh, GitHub's security team! 😂 With billions in their pocket and AI at their fingertips, they still can't find a digital virus in a haystack. Who knew the best malware detection tool was...the search bar? 🔍💰
https://orchidfiles.com/github-security-team/ #GitHubSecurity #AIDetection #MalwareSearch #DigitalVirus #HaystackHacks #HackerNews #ngated -
Oh, GitHub's security team! 😂 With billions in their pocket and AI at their fingertips, they still can't find a digital virus in a haystack. Who knew the best malware detection tool was...the search bar? 🔍💰
https://orchidfiles.com/github-security-team/ #GitHubSecurity #AIDetection #MalwareSearch #DigitalVirus #HaystackHacks #HackerNews #ngated -
Oh, GitHub's security team! 😂 With billions in their pocket and AI at their fingertips, they still can't find a digital virus in a haystack. Who knew the best malware detection tool was...the search bar? 🔍💰
https://orchidfiles.com/github-security-team/ #GitHubSecurity #AIDetection #MalwareSearch #DigitalVirus #HaystackHacks #HackerNews #ngated -
Oh, GitHub's security team! 😂 With billions in their pocket and AI at their fingertips, they still can't find a digital virus in a haystack. Who knew the best malware detection tool was...the search bar? 🔍💰
https://orchidfiles.com/github-security-team/ #GitHubSecurity #AIDetection #MalwareSearch #DigitalVirus #HaystackHacks #HackerNews #ngated -
Discover how the AgentBaiting malware campaign weaponized over 800 fake AI skills and MCP servers on GitHub to deliver StealC and SmartLoader.
#AgentBaiting #AIMalware #MCPServer #GitHubSecurity #InfoSec
https://meterpreter.org/agentbaiting-malware-campaign/?utm_source=mastodon&utm_medium=jetpack_social
-
Discover how the AgentBaiting malware campaign weaponized over 800 fake AI skills and MCP servers on GitHub to deliver StealC and SmartLoader.
#AgentBaiting #AIMalware #MCPServer #GitHubSecurity #InfoSec
https://meterpreter.org/agentbaiting-malware-campaign/?utm_source=mastodon&utm_medium=jetpack_social
-
🤣 Oh joy, another thrilling GitHub epic where devs pretend to care about security while drooling over AI code suggestions! 🚀 It’s like watching paint dry, but with more #buzzwords and less substance. 💻🔒
https://github.com/SmtimesIWndr/gdid-reversal #GitHubSecurity #AIcodeSuggestions #DeveloperHumor #TechSatire #HackerNews #ngated -
🤣 Oh joy, another thrilling GitHub epic where devs pretend to care about security while drooling over AI code suggestions! 🚀 It’s like watching paint dry, but with more #buzzwords and less substance. 💻🔒
https://github.com/SmtimesIWndr/gdid-reversal #GitHubSecurity #AIcodeSuggestions #DeveloperHumor #TechSatire #HackerNews #ngated -
🤣 Oh joy, another thrilling GitHub epic where devs pretend to care about security while drooling over AI code suggestions! 🚀 It’s like watching paint dry, but with more #buzzwords and less substance. 💻🔒
https://github.com/SmtimesIWndr/gdid-reversal #GitHubSecurity #AIcodeSuggestions #DeveloperHumor #TechSatire #HackerNews #ngated -
🤣 Oh joy, another thrilling GitHub epic where devs pretend to care about security while drooling over AI code suggestions! 🚀 It’s like watching paint dry, but with more #buzzwords and less substance. 💻🔒
https://github.com/SmtimesIWndr/gdid-reversal #GitHubSecurity #AIcodeSuggestions #DeveloperHumor #TechSatire #HackerNews #ngated -
🤣 Oh joy, another thrilling GitHub epic where devs pretend to care about security while drooling over AI code suggestions! 🚀 It’s like watching paint dry, but with more #buzzwords and less substance. 💻🔒
https://github.com/SmtimesIWndr/gdid-reversal #GitHubSecurity #AIcodeSuggestions #DeveloperHumor #TechSatire #HackerNews #ngated -
Oh no! 😱 Another day, another GitHub fiasco. Someone apparently fell asleep at the security wheel 🚫🔒, and now we're all supposed to panic because "Mantine-datatable" got a time-out. Maybe next time, try locking the door before you leave the house... 🏠🔑🙄
https://github.com/icflorescu/mantine-datatable/discussions/813 #GitHubFail #GitHubSecurity #MantineDatatable #DeveloperOops #PanicMode #HackerNews #ngated -
Oh no! 😱 Another day, another GitHub fiasco. Someone apparently fell asleep at the security wheel 🚫🔒, and now we're all supposed to panic because "Mantine-datatable" got a time-out. Maybe next time, try locking the door before you leave the house... 🏠🔑🙄
https://github.com/icflorescu/mantine-datatable/discussions/813 #GitHubFail #GitHubSecurity #MantineDatatable #DeveloperOops #PanicMode #HackerNews #ngated -
Oh no! 😱 Another day, another GitHub fiasco. Someone apparently fell asleep at the security wheel 🚫🔒, and now we're all supposed to panic because "Mantine-datatable" got a time-out. Maybe next time, try locking the door before you leave the house... 🏠🔑🙄
https://github.com/icflorescu/mantine-datatable/discussions/813 #GitHubFail #GitHubSecurity #MantineDatatable #DeveloperOops #PanicMode #HackerNews #ngated -
Oh no! 😱 Another day, another GitHub fiasco. Someone apparently fell asleep at the security wheel 🚫🔒, and now we're all supposed to panic because "Mantine-datatable" got a time-out. Maybe next time, try locking the door before you leave the house... 🏠🔑🙄
https://github.com/icflorescu/mantine-datatable/discussions/813 #GitHubFail #GitHubSecurity #MantineDatatable #DeveloperOops #PanicMode #HackerNews #ngated -
Oh no! 😱 Another day, another GitHub fiasco. Someone apparently fell asleep at the security wheel 🚫🔒, and now we're all supposed to panic because "Mantine-datatable" got a time-out. Maybe next time, try locking the door before you leave the house... 🏠🔑🙄
https://github.com/icflorescu/mantine-datatable/discussions/813 #GitHubFail #GitHubSecurity #MantineDatatable #DeveloperOops #PanicMode #HackerNews #ngated -
Systemic Vulnerability: The Security Reality of GitHub Ecosystems
GitHub users face risks of credential leaks and AI data exposure due to hardcoded secrets and AI tool usage. Learn how to protect your code.
#GitHubSecurity, #CredentialLeak, #AIDataExposure, #DevOps, #CyberSecurity
https://newsletter.tf/github-security-credential-leak-ai-data/
-
GitHub users are at risk of credential leaks and AI data exposure. This is a critical issue for developers using AI tools like Copilot.
#GitHubSecurity, #CredentialLeak, #AIDataExposure, #DevOps, #CyberSecurity
https://newsletter.tf/github-security-credential-leak-ai-data/ -
🎉 Oh, look! Another riveting Windows update destined to "revolutionize" our lives by granting system user access to everyone and their grandmother. 🚀 And let's not forget about the obligatory GitHub plug—because who doesn't love sifting through endless repos to patch Microsoft's idea of security? 🙄
https://github.com/Nightmare-Eclipse/RedSun #WindowsUpdate #GitHubSecurity #UserAccess #TechHumor #MicrosoftPatch #HackerNews #ngated -
🎉 Oh, look! Another riveting Windows update destined to "revolutionize" our lives by granting system user access to everyone and their grandmother. 🚀 And let's not forget about the obligatory GitHub plug—because who doesn't love sifting through endless repos to patch Microsoft's idea of security? 🙄
https://github.com/Nightmare-Eclipse/RedSun #WindowsUpdate #GitHubSecurity #UserAccess #TechHumor #MicrosoftPatch #HackerNews #ngated -
🎉 Oh, look! Another riveting Windows update destined to "revolutionize" our lives by granting system user access to everyone and their grandmother. 🚀 And let's not forget about the obligatory GitHub plug—because who doesn't love sifting through endless repos to patch Microsoft's idea of security? 🙄
https://github.com/Nightmare-Eclipse/RedSun #WindowsUpdate #GitHubSecurity #UserAccess #TechHumor #MicrosoftPatch #HackerNews #ngated -
🎉 Oh, look! Another riveting Windows update destined to "revolutionize" our lives by granting system user access to everyone and their grandmother. 🚀 And let's not forget about the obligatory GitHub plug—because who doesn't love sifting through endless repos to patch Microsoft's idea of security? 🙄
https://github.com/Nightmare-Eclipse/RedSun #WindowsUpdate #GitHubSecurity #UserAccess #TechHumor #MicrosoftPatch #HackerNews #ngated -
🎉 Oh, look! Another riveting Windows update destined to "revolutionize" our lives by granting system user access to everyone and their grandmother. 🚀 And let's not forget about the obligatory GitHub plug—because who doesn't love sifting through endless repos to patch Microsoft's idea of security? 🙄
https://github.com/Nightmare-Eclipse/RedSun #WindowsUpdate #GitHubSecurity #UserAccess #TechHumor #MicrosoftPatch #HackerNews #ngated -
GitHub Bolsters Secret Scanning, Enhancing API and Workflow Integrations
GitHub improved secret scanning. Developers can now use new API filters and get more details in workflows to manage leaked secrets better. This helps teams fix security issues faster.
#GitHubSecurity, #SecretScanning, #APIIntegration, #DevOps, #CodeSecurity
https://newsletter.tf/github-secret-scanning-api-filters-workflow-help/
-
GitHub's secret scanning tools now offer more control. Developers can use new API filters and get detailed alerts, making it easier to find and fix leaked secrets in code.
#GitHubSecurity, #SecretScanning, #APIIntegration, #DevOps, #CodeSecurity
https://newsletter.tf/github-secret-scanning-api-filters-workflow-help/ -
🚨 CRITICAL: OpenAI Codex flaw risks GitHub token compromise — potential for repo manipulation & data theft. No CVE yet. Immediate action: audit, restrict, and rotate tokens in AI workflows. Details: https://radar.offseq.com/threat/critical-vulnerability-in-openai-codex-allowed-git-19b187ba #OffSeq #GitHubSecurity #AIsecurity
-
🚨 CRITICAL: OpenAI Codex flaw risks GitHub token compromise — potential for repo manipulation & data theft. No CVE yet. Immediate action: audit, restrict, and rotate tokens in AI workflows. Details: https://radar.offseq.com/threat/critical-vulnerability-in-openai-codex-allowed-git-19b187ba #OffSeq #GitHubSecurity #AIsecurity
-
🚨 CRITICAL: OpenAI Codex flaw risks GitHub token compromise — potential for repo manipulation & data theft. No CVE yet. Immediate action: audit, restrict, and rotate tokens in AI workflows. Details: https://radar.offseq.com/threat/critical-vulnerability-in-openai-codex-allowed-git-19b187ba #OffSeq #GitHubSecurity #AIsecurity
-
🚨 CRITICAL: OpenAI Codex flaw risks GitHub token compromise — potential for repo manipulation & data theft. No CVE yet. Immediate action: audit, restrict, and rotate tokens in AI workflows. Details: https://radar.offseq.com/threat/critical-vulnerability-in-openai-codex-allowed-git-19b187ba #OffSeq #GitHubSecurity #AIsecurity
-
Researchers have documented a campaign abusing GitHub repositories themed as OSINT tools, GPT utilities, and developer resources to deliver PyStoreRAT, a modular, multi-stage remote access trojan.
The operation leverages delayed malicious commits, minimal loader stubs, reputation manipulation, and HTA-based execution to reduce early detection. In parallel, a separate RAT campaign demonstrates region- and language-aware targeting logic.
These cases underscore evolving tradecraft around trust abuse and script-based implants.
How are you adapting repository vetting and execution controls in your environment?Source: https://thehackernews.com/2025/12/fake-osint-and-gpt-utility-github-repos.html
Engage in the discussion and follow TechNadu for measured infosec reporting.
#InfoSec #ThreatIntel #MalwareAnalysis #GitHubSecurity #OpenSourceRisk #TechNadu
-
Researchers have documented a campaign abusing GitHub repositories themed as OSINT tools, GPT utilities, and developer resources to deliver PyStoreRAT, a modular, multi-stage remote access trojan.
The operation leverages delayed malicious commits, minimal loader stubs, reputation manipulation, and HTA-based execution to reduce early detection. In parallel, a separate RAT campaign demonstrates region- and language-aware targeting logic.
These cases underscore evolving tradecraft around trust abuse and script-based implants.
How are you adapting repository vetting and execution controls in your environment?Source: https://thehackernews.com/2025/12/fake-osint-and-gpt-utility-github-repos.html
Engage in the discussion and follow TechNadu for measured infosec reporting.
#InfoSec #ThreatIntel #MalwareAnalysis #GitHubSecurity #OpenSourceRisk #TechNadu
-
Researchers have documented a campaign abusing GitHub repositories themed as OSINT tools, GPT utilities, and developer resources to deliver PyStoreRAT, a modular, multi-stage remote access trojan.
The operation leverages delayed malicious commits, minimal loader stubs, reputation manipulation, and HTA-based execution to reduce early detection. In parallel, a separate RAT campaign demonstrates region- and language-aware targeting logic.
These cases underscore evolving tradecraft around trust abuse and script-based implants.
How are you adapting repository vetting and execution controls in your environment?Source: https://thehackernews.com/2025/12/fake-osint-and-gpt-utility-github-repos.html
Engage in the discussion and follow TechNadu for measured infosec reporting.
#InfoSec #ThreatIntel #MalwareAnalysis #GitHubSecurity #OpenSourceRisk #TechNadu
-
Researchers have documented a campaign abusing GitHub repositories themed as OSINT tools, GPT utilities, and developer resources to deliver PyStoreRAT, a modular, multi-stage remote access trojan.
The operation leverages delayed malicious commits, minimal loader stubs, reputation manipulation, and HTA-based execution to reduce early detection. In parallel, a separate RAT campaign demonstrates region- and language-aware targeting logic.
These cases underscore evolving tradecraft around trust abuse and script-based implants.
How are you adapting repository vetting and execution controls in your environment?Source: https://thehackernews.com/2025/12/fake-osint-and-gpt-utility-github-repos.html
Engage in the discussion and follow TechNadu for measured infosec reporting.
#InfoSec #ThreatIntel #MalwareAnalysis #GitHubSecurity #OpenSourceRisk #TechNadu
-
Researchers have documented a campaign abusing GitHub repositories themed as OSINT tools, GPT utilities, and developer resources to deliver PyStoreRAT, a modular, multi-stage remote access trojan.
The operation leverages delayed malicious commits, minimal loader stubs, reputation manipulation, and HTA-based execution to reduce early detection. In parallel, a separate RAT campaign demonstrates region- and language-aware targeting logic.
These cases underscore evolving tradecraft around trust abuse and script-based implants.
How are you adapting repository vetting and execution controls in your environment?Source: https://thehackernews.com/2025/12/fake-osint-and-gpt-utility-github-repos.html
Engage in the discussion and follow TechNadu for measured infosec reporting.
#InfoSec #ThreatIntel #MalwareAnalysis #GitHubSecurity #OpenSourceRisk #TechNadu
-
Red Hat’s GitHub breach was more than a data leak—it was a wake-up call. A cyber crew snagged 570GB of critical code and sensitive info from giants like the U.S. Navy and Bank of America. Can we really afford to be this vulnerable?
https://thedefendopsdiaries.com/red-hat-github-breach-lessons-from-the-crimson-collective-attack/
#redhatbreach
#githubsecurity
#cyberattack
#authenticationtokens
#incidentresponse -
Red Hat’s GitHub breach was more than a data leak—it was a wake-up call. A cyber crew snagged 570GB of critical code and sensitive info from giants like the U.S. Navy and Bank of America. Can we really afford to be this vulnerable?
https://thedefendopsdiaries.com/red-hat-github-breach-lessons-from-the-crimson-collective-attack/
#redhatbreach
#githubsecurity
#cyberattack
#authenticationtokens
#incidentresponse -
Red Hat’s GitHub breach was more than a data leak—it was a wake-up call. A cyber crew snagged 570GB of critical code and sensitive info from giants like the U.S. Navy and Bank of America. Can we really afford to be this vulnerable?
https://thedefendopsdiaries.com/red-hat-github-breach-lessons-from-the-crimson-collective-attack/
#redhatbreach
#githubsecurity
#cyberattack
#authenticationtokens
#incidentresponse -
🚨 Fake Malwarebytes, LastPass & 70+ brands abused on GitHub to spread Atomic Stealer (AMOS).
🔹 Fake repos + SEO + sponsored ads = malware installs
🔹 Copy-paste terminal commands (curl … | bash) deliver the payload instantly
🔹 Brands targeted include password managers, fintech apps, and dev tools
⚠️ Another reminder: only trust official developer sites.
💬 Do you think GitHub & Google should be held more accountable for catching these campaigns earlier?Follow @technadu for #CyberSecurity insights.
#Malware #AtomicStealer #AMOS #Infostealer #MacOS #Malwarebytes #LastPass #GitHubSecurity
-
🚨 Fake Malwarebytes, LastPass & 70+ brands abused on GitHub to spread Atomic Stealer (AMOS).
🔹 Fake repos + SEO + sponsored ads = malware installs
🔹 Copy-paste terminal commands (curl … | bash) deliver the payload instantly
🔹 Brands targeted include password managers, fintech apps, and dev tools
⚠️ Another reminder: only trust official developer sites.
💬 Do you think GitHub & Google should be held more accountable for catching these campaigns earlier?Follow @technadu for #CyberSecurity insights.
#Malware #AtomicStealer #AMOS #Infostealer #MacOS #Malwarebytes #LastPass #GitHubSecurity
-
🚨 Fake Malwarebytes, LastPass & 70+ brands abused on GitHub to spread Atomic Stealer (AMOS).
🔹 Fake repos + SEO + sponsored ads = malware installs
🔹 Copy-paste terminal commands (curl … | bash) deliver the payload instantly
🔹 Brands targeted include password managers, fintech apps, and dev tools
⚠️ Another reminder: only trust official developer sites.
💬 Do you think GitHub & Google should be held more accountable for catching these campaigns earlier?Follow @technadu for #CyberSecurity insights.
#Malware #AtomicStealer #AMOS #Infostealer #MacOS #Malwarebytes #LastPass #GitHubSecurity
-
GitHub notifications trusted you, right? Now imagine them doubling as a gateway for a Y Combinator scam that stole crypto. One subtle typo in a domain and hackers had developers in their sights. Stay vigilant—this one’s a wake-up call!
#githubsecurity
#phishing
#cryptotheft
#socialengineering
#infosec
#web3security
#zerotrust
#cybersecurity
#domainspoofing -
GitHub notifications trusted you, right? Now imagine them doubling as a gateway for a Y Combinator scam that stole crypto. One subtle typo in a domain and hackers had developers in their sights. Stay vigilant—this one’s a wake-up call!
#githubsecurity
#phishing
#cryptotheft
#socialengineering
#infosec
#web3security
#zerotrust
#cybersecurity
#domainspoofing -
GitHub notifications trusted you, right? Now imagine them doubling as a gateway for a Y Combinator scam that stole crypto. One subtle typo in a domain and hackers had developers in their sights. Stay vigilant—this one’s a wake-up call!
#githubsecurity
#phishing
#cryptotheft
#socialengineering
#infosec
#web3security
#zerotrust
#cybersecurity
#domainspoofing -
GitHub is shaking up npm security—mandatory 2FA and short-lived, permission-specific tokens could be a game changer against supply-chain attacks. Are we finally outsmarting cyber threats?
-
GitHub is shaking up npm security—mandatory 2FA and short-lived, permission-specific tokens could be a game changer against supply-chain attacks. Are we finally outsmarting cyber threats?
-
GitHub is shaking up npm security—mandatory 2FA and short-lived, permission-specific tokens could be a game changer against supply-chain attacks. Are we finally outsmarting cyber threats?
-
SEO poisoning + GitHub Pages hosting are delivering HiddenGh0st, Winos & kkRAT installers that evade AV (BYOVD), hijack clipboard addresses, and load modular RAT plugins.
Recommended: block disposable TLDs, enforce installer allowlists, monitor startup shortcuts/TypeLib changes, and flag unusual scheduled tasks/process renames. Discuss your mitigations — follow @technadu.
#InfoSec #Malware #ThreatIntel #RAT #SEOpoisoning #GitHubSecurity
-
SEO poisoning + GitHub Pages hosting are delivering HiddenGh0st, Winos & kkRAT installers that evade AV (BYOVD), hijack clipboard addresses, and load modular RAT plugins.
Recommended: block disposable TLDs, enforce installer allowlists, monitor startup shortcuts/TypeLib changes, and flag unusual scheduled tasks/process renames. Discuss your mitigations — follow @technadu.
#InfoSec #Malware #ThreatIntel #RAT #SEOpoisoning #GitHubSecurity
-
SEO poisoning + GitHub Pages hosting are delivering HiddenGh0st, Winos & kkRAT installers that evade AV (BYOVD), hijack clipboard addresses, and load modular RAT plugins.
Recommended: block disposable TLDs, enforce installer allowlists, monitor startup shortcuts/TypeLib changes, and flag unusual scheduled tasks/process renames. Discuss your mitigations — follow @technadu.
#InfoSec #Malware #ThreatIntel #RAT #SEOpoisoning #GitHubSecurity
-
Hackers disguised their way into GitHub by faking security updates—327 accounts, 817 repos, and 3,325 secrets compromised. It’s a stark reminder to double-check every “security patch.”
https://thedefendopsdiaries.com/ghostaction-github-attack-a-wake-up-call-for-software-security/
#githubsecurity
#supplychainattack
#cyberthreats
#infosec
#softwaresecurity -
Hackers disguised their way into GitHub by faking security updates—327 accounts, 817 repos, and 3,325 secrets compromised. It’s a stark reminder to double-check every “security patch.”
https://thedefendopsdiaries.com/ghostaction-github-attack-a-wake-up-call-for-software-security/
#githubsecurity
#supplychainattack
#cyberthreats
#infosec
#softwaresecurity -
Hackers disguised their way into GitHub by faking security updates—327 accounts, 817 repos, and 3,325 secrets compromised. It’s a stark reminder to double-check every “security patch.”
https://thedefendopsdiaries.com/ghostaction-github-attack-a-wake-up-call-for-software-security/
#githubsecurity
#supplychainattack
#cyberthreats
#infosec
#softwaresecurity -
Salesloft’s GitHub breach is a wake-up call—sophisticated phishing, API loopholes, and insider risks left them exposed. Could your code be next? Dive into the lessons and protect your digital assets before it’s too late.
#salesloftbreach
#cybersecurity
#githubsecurity
#phishing
#apivulnerabilities -
Salesloft’s GitHub breach is a wake-up call—sophisticated phishing, API loopholes, and insider risks left them exposed. Could your code be next? Dive into the lessons and protect your digital assets before it’s too late.
#salesloftbreach
#cybersecurity
#githubsecurity
#phishing
#apivulnerabilities -
Salesloft’s GitHub breach is a wake-up call—sophisticated phishing, API loopholes, and insider risks left them exposed. Could your code be next? Dive into the lessons and protect your digital assets before it’s too late.
#salesloftbreach
#cybersecurity
#githubsecurity
#phishing
#apivulnerabilities -
🔒 HIGH severity: Salesloft & Drift breach via GitHub compromise and stolen OAuth tokens. Risks include data exposure and lateral movement. Audit & revoke tokens, enforce MFA, monitor access. No CVE. Read more: https://radar.offseq.com/threat/salesloft-drift-breach-traced-to-github-compromise-9684276c #OffSeq #OAuth #GitHubSecurity
-
🔒 HIGH severity: Salesloft & Drift breach via GitHub compromise and stolen OAuth tokens. Risks include data exposure and lateral movement. Audit & revoke tokens, enforce MFA, monitor access. No CVE. Read more: https://radar.offseq.com/threat/salesloft-drift-breach-traced-to-github-compromise-9684276c #OffSeq #OAuth #GitHubSecurity
-
🔒 HIGH severity: Salesloft & Drift breach via GitHub compromise and stolen OAuth tokens. Risks include data exposure and lateral movement. Audit & revoke tokens, enforce MFA, monitor access. No CVE. Read more: https://radar.offseq.com/threat/salesloft-drift-breach-traced-to-github-compromise-9684276c #OffSeq #OAuth #GitHubSecurity
-
🎉 Breaking news: Typo alert! Some genius decided to check if misspelling "ghcr.io" as "ghrc.io" would lead to a secret Nginx rave 🕺—only to discover it's a phishing scam instead. Who knew a single letter could compromise your GitHub creds faster than you can say "oops"? 🤦♂️
https://bmitch.net/blog/2025-08-22-ghrc-appears-malicious/ #TypoAlert #PhishingScam #GitHubSecurity #NginxRave #CyberSecurity #HackerNews #ngated