Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

GitHub

20 articles

Security Affairs Malware GitHub 10h ago

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 98

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Popu...

T1195

Security Affairs →

BleepingComputer Campaigns GitHub 1d ago

Laravel Lang packages hijacked to deploy credential-stealing malware

A supply chain attack targeting the Laravel Lang localization packages has exposed developers to a sophisticated credential-stealing malware campaign after a...

T1195

BleepingComputer →

The Hacker News Supply Chain GitHub 1d ago

npm Adds 2FA-Gated Publishing and Package Install Controls Against Supply Chain Attacks

GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly approve a relea...

T1195 T1598

The Hacker News →

GBHackers Vulnerability Disclosure GitHub 1d ago

Hackers Compromise Laravel-Lang Packages via 700 GitHub Repos

A sophisticated and active supply chain attack has struck the Laravel-Lang open-source organization, compromising over 700 historical package versions across...

T1190 T1195

GBHackers →

SC Media General GitHub 2d ago

TVs, Old York, Flipper One, Ubiquity, Underminr, CISOs, GitHub, Josh Marpet... - SWN #583

SC Media →

HackRead Supply Chain GitHub 2d ago

5,561 GitHub Repositories Hit by Megalodon Supply Chain Attack in Six Hours

SafeDep uncovered the Megalodon attack targeting 5,561 GitHub repositories with malicious CI workflows and cloud credential theft.

T1078 T1195

HackRead →

The Hacker News Campaigns GitHub 2d ago

Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows

Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561 GitHub reposit...

T1041

The Hacker News →

Trail of Bits Malware GitHub 2d ago

We hardened zizmor's GitHub Actions static analyzer

In March 2026, attackers exploited a pull_request_target misconfiguration in the aquasecurity/trivy-action GitHub Action to exfiltrate organization and repos...

T1041

Trail of Bits →

SecurityWeek Supply Chain GitHub 2d ago

Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack

Hackers accessed Grafana’s GitHub repositories after a token compromised in the TanStack attack was not rotated. The post Grafana Says Codebase and Other Dat...

T1041 T1195

SecurityWeek →

GBHackers Campaigns GitHub 2d ago

Megalodon Malware Rapidly Infects Over 5,500 GitHub Repositories

A newly identified malware campaign dubbed “Megalodon” has compromised more than 5,500 GitHub repositories, raising serious concerns about the security of op...

GBHackers →

SC Media Supply Chain GitHub 3d ago

FCC, Github, MiniShai-hulud, Stated of Supply Chain, Itron, CRA, NIS2, and more!! - PSW #927

SC Media →

SC Media Data Breach GitHub 3d ago

Senator urges classified briefing after CISA data leak on GitHub

A GitHub leak exposed CISA credentials, sparking concerns over secrets management and leadership.

SC Media →

Infosecurity Magazine Data Breach GitHub 3d ago

GitHub Breach Traced to Malicious 'Nx Console' VS Code Extension

A threat actor compromised an Nx developer and posed as a legitimate maintainer to publish a malicious extension on Visual Studio Marketplace

Infosecurity Magazine →

Help Net Security Data Breach GitHub 3d ago

GitHub, Grafana Labs breaches traced back to TanStack supply chain compromise

GitHub CISO Alexis Wales has named the malicious VS Code extension behind the breach they suffered at the hands of the threat group TeamPCP: Nx Console, a po...

T1041 T1195

Help Net Security →

BleepingComputer Data Breach GitHub 3d ago

GitHub links repo breach to TanStack npm supply-chain attack

GitHub says the hackers who breached 3,800 internal repositories gained access via a malicious version of the Nx Console VS Code extension, compromised in la...

BleepingComputer →

SC Media Campaigns GitHub 4d ago

New Mini Shai-Hulud attack targets npm ecosystem

Mini Shai-Hulud campaign hits 323 npm packages, GitHub Actions and VS Code tools.

SC Media →

BleepingComputer Data Breach GitHub 4d ago

Grafana breach caused by missed token rotation after TanStack attack

The Grafana data breach was caused by a single GitHub workflow token that slipped through the rotation process following the TanStack npm supply-chain attack...

BleepingComputer →

HackRead Data Breach GitHub 4d ago

GitHub Breach: TeamPCP Steals 3,800 Repositories via VS Code Extension

GitHub Breach: TeamPCP stole 3,800 internal repositories through a malicious VS Code extension and is now selling the data online for $95,000.

HackRead →

GBHackers Data Breach GitHub 4d ago

Grafana GitHub Security Incident Reportedly Connected to TanStack npm Ransomware

Grafana Labs has disclosed a targeted GitHub security incident linked to the ongoing TanStack npm supply chain ransomware campaign, raising concerns about so...

GBHackers →

The Record Data Breach GitHub 4d ago

GitHub confirms being hacked by TeamPCP, says customer data unaffected

Github, which hosts code for more than 100 million developers worldwide, confirmed the breach on social media after TeamPCP advertised stolen source code on ...

The Record →

1 2 3 4 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA