A GitHub employee has unwittingly allowed 3,800 internal repositories to be breached after a device compromise with a ...
GitHub has confirmed that hackers breached internal repositories through a poisoned VS Code extension after stolen source ...
Threat actors impersonate GitHub's security and recruitment teams in phishing attacks to hijack repositories using malicious OAuth apps in an ongoing extortion campaign wiping compromised repos. The ...
TeamPCP’s Mini Shai-Hulud campaign used hijacked GitHub OIDC tokens to spread a credential-stealing worm through TanStack npm ...