A large-scale supply chain attack dubbed FakeGit uses thousands of deceptive GitHub repositories to distribute SmartLoader malware.
CISA publishes forensic analysis of May 2026 credential leak from contractor GitHub account
A CISA contractor accidentally exposed AWS access keys and admin credentials on a personal GitHub account, sparking a major security…
Attackers are using networks of dormant GitHub accounts to map corporate development teams and steal source code.
A North Korean threat group is targeting developers with phishing emails that lead to malicious VS Code projects, deploying cross…
CVE-2026-3854 allowed any authenticated user to compromise GitHub backend servers via injected git push options, exposing millions of private repositories.…
Sign in to your account