news.mlab.sh
Back to the feed
supply-chain

GitHub dismissed security reports on flaws now exploited by supply-chain worm, researchers say

High
Image: The Record
Summary

A supply-chain worm, dubbed Shai-Hulud, is exploiting design flaws in GitHub to infect hundreds of software packages and developer accounts worldwide. The vulnerabilities, initially flagged by Deep Specter Research, were dismissed by GitHub as ineligible, allowing the TeamPCP cybercrime group and copycat entities to compromise systems including the European Commission, Mercor, and Red Hat. The situation highlights concerns about GitHub's vulnerability reporting process and the broader security landscape surrounding open-source software.

Read the full article at The Record

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.