Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

GitHub

20 articles

SecurityWeek general GitHub Linux 4d ago

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug

Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification. ...

T1498

SecurityWeek → Details

SC Media general GitHub 4d ago

Over 50,000 Stripe API keys exposed, highlighting fraud risks

Over 50,000 Stripe API keys have been exposed across public code repositories, GitHub Actions logs, and misconfigured web servers, demonstrating the immediat...

SC Media → Details

CSO Online enterprise GitHub 6d ago

Snowflake flaw slips past AI checks, gets exploited by another AI

An autonomous AI security agent developed by cloud security firm Wiz identified and exploited a critical vulnerability in Snowflake’s GitHub Actions pipeline...

CSO Online → Details

Security Affairs general GitHub 6d ago

50,000 Stripe Secrets Leaked in Public Code

Over 50,000 exposed Stripe API keys show how leaked secrets can enable fraud, data access and account abuse within hours. Ransomnews researchers have documen...

Security Affairs → Details

SC Media general GitHub 6d ago

Secrets, Red Agent, GitHub, evoooo1bot, DecryptAds, Copilot, Aaran Leyland, and More - SWN #608

SC Media → Details

Infosecurity Magazine general GitHub Aug 18

Wiz AI Agent Finds Critical Snowflake GitHub Repo Flaw Advanced Security Missed

The security flaw in Snowflake’s GitHub Actions workflow had been missed by a GitHub Advanced Security scan, said a Wiz researcher

Infosecurity Magazine → Details

GBHackers general GitHub Aug 18

C2Looper v2 Uses GitHub Repositories as Full Command-and-Control Infrastructure.

C2Looper, a Rust-based backdoor likely associated with a ransomware-related threat actor. A newer build, internally identified as version 2, replaces convent...

GBHackers → Details

The Hacker News general GitHub Intel Aug 18

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

The U.S.

The Hacker News → Details

Help Net Security general GitHub Salesforce ServiceNow Aug 16

Week in review: Salesforce and ServiceNow portals exposed for 17 months, exploited Metabase 0-day

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: GitHub Dependabot malware alerts now cover eight ecosystems...

T1598 1 IOC

Help Net Security → Details

SC Media general GitHub Aug 13

Market for AI watermark removal tools emerges after Anthropic's Claude update

This development includes a GitHub project with over 4,500 stars, various new web tools, and existing AI detection evasion services.

SC Media → Details

BleepingComputer general GitHub Aug 13

AI 'watermark removers' flood the web. Almost none can prove they work.

Multiple 'watermark removers' have surfaced days after Anthropic began watermarking text generated by Claude, including an open source project with over 4,50...

BleepingComputer → Details

BleepingComputer general GitHub Aug 11

Mozilla updates GPG signing key for Firefox releases after exposure

Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. [.

BleepingComputer → Details

GBHackers general GitHub Linux Aug 11

Mozilla Rotates Firefox and Thunderbird GPG Signing Key After Private GitHub Exposure

Mozilla has rotated a GPG signing subkey used to authenticate release artifacts for Firefox and Thunderbird after an unencrypted copy of the previous subkey ...

GBHackers → Details

SecurityWeek general GitHub Aug 11

Mozilla Issues New Firefox GPG Key Following Exposure

The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it. The post Mozilla Issues New Firefox GPG Key ...

SecurityWeek → Details

GBHackers general GitHub Aug 10

GitHub Expands Dependabot Malware Alerts to Detect Malicious Packages Across 8 Ecosystems

GitHub has expanded its Dependabot malware alerts beyond npm, enabling the detection of malicious dependencies across various package ecosystems, including P...

1 IOC

GBHackers → Details

Security Affairs general GitHub Aug 10

A GitHub Misconfiguration Let Kimi K3 Cheat a Cybersecurity Benchmark

Kimi K3 bypassed a UK cybersecurity test by accessing GitHub, cloning the benchmark and reading its solutions instead of solving the challenge Sometimes the ...

Security Affairs → Details

Help Net Security general GitHub Aug 10

GitHub Dependabot malware alerts now cover eight ecosystems

GitHub has flagged npm malware since March 2026. Anyone pulling in a bad PyPI, Maven, RubyGems, NuGet, Go, crates.

T1598 1 IOC

Help Net Security → Details

Help Net Security general GitHub GitLab Aug 10

Chainloop: Open-source evidence store and policy engine for the software supply chain

Chainloop is an open source evidence store for the software supply chain. A command line tool runs inside a GitHub Actions, GitLab, Jenkins, or Dagger pipeli...

T1195

Help Net Security → Details

Unit 42 research GitHub Aug 6

ChainDrop: Inside a Self-Propagating npm Worm

Analysis of ChainDrop, an npm supply chain worm extracting GitHub Actions runner secrets and using Ethereum smart contracts for C2 routing. The post ChainDro...

Unit 42 → Details

SANS ISC advisories GitHub Aug 5

Don't Revoke That Token Yet: Inside the keyv/cacheable npm Worm, (Wed, Aug 5th)

When you learn that a compromised package executed on one of your build hosts, muscle memory takes over: revoke the npm token, rotate the GitHub PAT, cycle t...

T1598

SANS ISC → Details

1 2 3 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA