Follow Cyber Kendra on Google News! | WhatsApp | Telegram

Add as a preferred source on Google
GitHub

GitHub Down as Outage Hits Actions, API and Copilot

Status: MOSTLY RECOVERED — COPILOT STILL DOWN. At 16:59 UTC GitHub declared the degradation mitigated across API Requests, Actions, Git Operati…

GitHub Source Code Allegedly Up for Sale Again

The internal source code stolen from GitHub in May is allegedly back on the market, and this time the seller is showing samples to prove it. A listi…

Most GitHub Enterprise Servers Still Unpatched for New RCE

Nearly nine out of ten self-hosted GitHub Enterprise Server instances remain vulnerable to a critical remote code execution flaw that needs nothing m…

Researcher Drops PoC for 1-Click GitHub Token Theft via VSCode Bug — Skips MSRC Entirely

Security researcher Ammar Askar has publicly released a fully working proof-of-concept (PoC) exploit that can steal a victim's GitHub OAuth token…

Composer Bug Silently Dumped GitHub Tokens Into CI Logs — Patch Now

Millions of PHP developers who rely on Composer for dependency management were silently exposed to a token-leaking vulnerability this week — one that…

A Single Git Push Was All It Took to Compromise GitHub — Millions of Repos Were Exposed

A critical vulnerability in GitHub's internal infrastructure allowed any authenticated user to execute arbitrary commands on GitHub's backend…

AI-Powered GitHub Bot Quietly Targeted 500+ Repositories for Three Weeks Before Anyone Noticed

A threat actor armed with AI-assisted automation spent three weeks silently probing open-source repositories before security researchers caught on — …

Sha1-Hulud 2.0: Destructive Worm Hijacks 25,000+ GitHub Repos in Massive NPM Supply Chain Attack

Over 700 npm packages compromised as self-replicating malware targets developer credentials across Zapier, PostHog, Postman, and ENS Domains—with a s…

GhostAction Attack Exposes 3,325 Developer Secrets in Massive GitHub Supply Chain Breach

A supply chain attack dubbed " GhostAction " has compromised 327 GitHub users across 817 repositories, successfully exfiltrating 3,325 sens…

Researcher Uncovers Critical Git Credential Theft Vulnerabilities

Critical security vulnerabilities in popular Git-related tools could allow attackers to steal user credentials, according to research published by G…

GitHub Launch Spark - Added Claude and Gemini Support to Copilot

GitHub has announced two major developments that could reshape how developers interact with AI tools: the launch of GitHub Spark, a revolutionary AI-…

GitHub Launches AI Engineering Platform "GitHub Models"

GitHub has announced the launch of "GitHub Models," a new platform that brings cutting-edge AI models directly to its community of over 100…

GitHub Rotates Credentials and Releases Critical Security Patch for Enterprise Server

GitHub revealed that it has rotated several critical credentials on GitHub.com in response to a vulnerability reported through its Bug Bounty program…

Addressing the Top CI/CD Challenges for Distributed Teams

Whenever we talk about distributed teams, the first attribute that comes to mind is that it is productivity agnostic—your team can work on various pa…