Skip to main content
FreeIntelHub
Feed Threat Feed Search Trending
Intelligence CVE Priority Vulnerability IOC Lookup IOC Feed YARA Rules Phishing Lookup Exploit Lookup Pastes Dark Web
Adversaries Threat Groups Software Campaigns
Explore Dashboard Geo Map Heatmap MITRE ATT&CK
Browse Directory Sources Vendors Categories Sectors
RSS API
FreeIntelHub
/
Sign In

GitHub

20 articles

The Hacker News general GitHub Aug 5

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to ...

T1078

The Hacker News → Details

SecurityWeek general GitHub Aug 5

Over 400 NPM Packages Infected in ChainDrop Supply Chain Attack

The malware was designed to steal and exfiltrate secrets, and to propagate itself via stolen NPM and GitHub credentials. The post Over 400 NPM Packages Infec...

T1041 T1195

SecurityWeek → Details

CSO Online enterprise GitHub Aug 4

ChainDrop credential stealing worm infects over 400 npm packages

A self-propagating worm-like attack is hitting the npm registry, having infected 444 packages from more than a dozen publishers so far. The impact is massive...

CSO Online → Details

HackRead general GitHub Aug 4

Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages

Shai-Hulud npm worm spreads through Keyv and hundreds of packages with 2 billion monthly downloads, stealing npm, GitHub, cloud and CI credentials in real time.

HackRead → Details

Cloudflare Blog vendor GitHub Aug 4

How we built a software factory to drive Astro’s GitHub issue count to zero

By replacing manual issue verification with isolated AI subagents running in GitHub Actions, the Astro maintainers reduced open issue count by 85%. This post...

Cloudflare Blog → Details

Help Net Security general GitHub Docker Aug 4

Uptime Kuma 2.5.0 waits two weeks before trusting a new npm package

Uptime Kuma checks whether a website, a Docker container, a DNS record, or a Steam game server is still answering, and pushes a message to Telegram, Slack, o...

Help Net Security → Details

GBHackers general GitHub Aug 4

Fake AI Tools Target Developers With Infostealers to Steal Credentials and Cloud Secrets

A large-scale malware campaign targeting developers and AI users has been uncovered ,revealing how attackers are weaponizing fake AI tools and cloned GitHub ...

T1204 T1041

GBHackers → Details

GBHackers general GitHub Linux Jul 31

BlackTech APT Uses New BlueShell Linux Backdoor in Attacks on Japanese Organizations

BlackTech, a long-running China-aligned APT group, has adopted a new Linux backdoor built on the BlueShell open-source RAT to conduct post-intrusion operatio...

GBHackers → Details

Help Net Security general GitHub Jul 29

1Password targets standing privileges with new access management capabilities

1Password has launched 1Password Privileged Access, extending the 1Password Unified Access platform with privileged access management (PAM). It enables just-...

Help Net Security → Details

GBHackers general GitHub Jul 28

Operation STANDOFF Uses GitHub Redirects Across 44 Servers to Hide Multi-Malware C2 Traffic

Operation STANDOFF is a Russian‑speaking cybercriminal campaign that uses a cluster of at least 44 TimeWeb‑hosted servers that all masquerade as benign GitHu...

GBHackers → Details

SC Media general GitHub Jul 27

GitHub and PyPI implement new security measures against supply-chain attacks

Based on information from Bleeping Computer, GitHub and the Python Package Index (PyPI) have introduced new time-based security mechanisms within their devel...

SC Media → Details

SecurityWeek general GitHub Jul 27

New GitHub, PyPI Policies Boost Supply Chain Security

Dependabot gets a three-day cooldown window before opening pull requests, and PyPI rejects file uploads to releases older than 14 days. The post New GitHub, ...

SecurityWeek → Details

GBHackers general GitHub Jul 27

GitHub Adds Dependabot Cooldown to Stop Poisoned Dependencies

GitHub has introduced a default cooldown period for Dependabot version updates to decrease the risk of organizations automatically adopting malicious or comp...

T1195

GBHackers → Details

Help Net Security general GitHub Jul 27

GitHub delays version updates so malware gets caught first

An automated update tool watches a package registry, catches a new release the moment it publishes, and opens a pull request for your team. That is the job i...

Help Net Security → Details

BleepingComputer general GitHub Jul 26

GitHub, PyPI add time-absed defenses against supply chain attacks

GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain at...

T1195

BleepingComputer → Details

SC Media general GitHub Jul 24

GitHub to implement two-tier bug bounty program amid AI-generated report surge

GitHub is launching a two-tier bug bounty program starting July 27, 2026, in response to an increase in low-quality, AI-generated vulnerability reports.

SC Media → Details

The Hacker News general GitHub Jul 23

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure de...

The Hacker News → Details

GBHackers general GitHub Jul 23

Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers

Hackers are abusing compromised GitHub repositories and GitHub Actions workflows to build a de facto global botnet that scans and exploits web hosting server...

GBHackers → Details

Help Net Security general GitHub Jul 23

GitHub revamps bug bounty program with new VIP tier, payout changes

GitHub is changing its bug bounty program to reward higher-quality vulnerability reports and reduce low-effort submissions, including AI-generated reports. T...

Help Net Security → Details

The Hacker News general GitHub Jul 22

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000...

The Hacker News → Details

«Previous page 1 2 3 Next page»
FreeIntelHub · Open-source CTI platform

All articles belong to their respective owners. FreeIntelHub aggregates publicly available RSS feeds for informational purposes only. DMCA