supply-chain Network of 200 GitHub Repositories Used for Malware Infection A threat actor, linked to previous activity associated with the ‘ischhfd83’ email address, has created a network of over 200 GitHub repositories delivering Windows malware through a Go module disguised as a DNS scanning… SecurityWeek · Jul 10, 2026 High supply chaingithubmalware
threat-intel Dormant GitHub Accounts Help Attackers Blend In While Mapping Corporate Orgs Datadog Security Labs has discovered a campaign where attackers are systematically mapping corporate GitHub organizations by leveraging dormant accounts and stolen credentials to gather extensive information about a comp… The Hacker News · Jul 9, 2026 Medium githubenumerationapi
threat-intel GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures A vulnerability has been discovered in GitHub's signature verification process. Attackers can rewrite signed Git commits, creating new commits with the same content but a different hash, while still appearing as "Verifie… The Hacker News · Jul 8, 2026 High gitsignaturevulnerability
threat-intel Critical Vulnerability Exposes GitHub Agentic Workflows to Prompt Injection A critical vulnerability, dubbed GitLost, has been identified in GitHub Agentic Workflows, allowing unauthenticated attackers to potentially leak private repository data by injecting prompts into public GitHub Issues. Th… SecurityWeek · Jul 8, 2026 Critical prompt injectionai securityagentic ai
threat-intel 'GitLost' Flaw Leaks Private Data from GitHub's Agentic Workflows A critical prompt injection vulnerability, dubbed ‘GitLost,’ has been discovered in GitHub’s Agentic Workflows, allowing unauthenticated attackers to steal private data from an organization’s repositories by crafting a G… Dark Reading · Jul 7, 2026 High prompt injectionagentic aisecurity vulnerability
threat-intel Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data Researchers at Noma Security discovered a vulnerability, dubbed ‘GitLost,’ in GitHub Agentic Workflows that allows attackers to trick AI agents into leaking private repository content simply by posting a malicious issue… The Hacker News · Jul 7, 2026 High prompt injectionai agentgithub
supply-chain North Korean Hackers Target Open Source Developers in Supply Chain Attacks North Korean hackers, linked to the Contagious Interview operation, are engaging in a sophisticated supply chain attack targeting open-source developers. They are leveraging compromised GitHub repositories and malicious… SecurityWeek · Jul 6, 2026 High KRsupply-chaingithubopen-source
threat-intel North Korean Hackers Publish 108 Malicious Packages and Extensions in PolinRider Campaign North Korean threat actors, linked to the Contagious Interview campaign, have been publishing 108 malicious packages and extensions across platforms like npm, Packagist, and Go, as part of the PolinRider operation. This… The Hacker News · Jul 4, 2026 High KPnorth koreangithubmalware
threat-intel ‘BioShocking’ Attack Tricks AI Browsers Into Stealing Credentials Researchers at LayerX discovered a vulnerability dubbed ‘BioShocking’ that exploits the tendency of AI browsers to prioritize game-like objectives over security protocols. The attack leverages a puzzle-solving scenario t… SecurityWeek · Jul 2, 2026 High aibrowsercredentials
malware New ChocoPoC RAT Targets Vulnerability Researchers via Fake PoC Exploit Repos A new remote access trojan (RAT) called ChocoPoC is targeting vulnerability researchers through deceptive proof-of-concept (PoC) repositories on GitHub. The malware, disguised within Python dependencies, steals sensitive… The Hacker News · Jul 2, 2026 High CVE-2025-64446CVE-2025-55182CVE-2025-14847KRproof-of-conceptremote access trojangithub
threat-intel New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials A LayerX security firm discovered a new attack technique, dubbed BioShocking, that exploits AI browsers to trick users into revealing their login credentials. The method involves manipulating the AI browser into believin… The Hacker News · Jun 30, 2026 High N/aiprompt injectioncredential theft
supply-chain Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks A new vulnerability, dubbed 'Cordyceps,' has been discovered in CI/CD workflows, allowing unauthorized access and control over hundreds of GitHub repositories across major tech companies. The flaw stems from overly permi… The Hacker News · Jun 24, 2026 Critical cicdsupply chaingithub
supply-chain GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns GitHub is implementing a security update to its "actions/checkout" action to mitigate a common supply chain attack vector. The update, effective June 18, 2026, will block the execution of malicious code from untrusted fo… The Hacker News · Jun 23, 2026 High supply-chaingithubactions
vulnerability Microsoft fixes AutoGen Studio flaw that enabled code execution A vulnerability, dubbed AutoJack, was discovered in Microsoft’s AutoGen Studio, a framework for building multi-agent AI systems. The flaw allowed attackers to execute arbitrary commands on a host system by manipulating a… BleepingComputer · Jun 22, 2026 Medium aiagentremote code execution
threat-intel Novo Nordisk Breach Exposes Software Development Pipeline Risk A breach at Novo Nordisk, facilitated by a leaked GitHub token, exposed a significant amount of sensitive data, including patient clinical trial information, healthcare professional records, and proprietary drug developm… Dark Reading · Jun 18, 2026 High DKgithubsecretssupply-chain
supply-chain GitHub dismissed security reports on flaws now exploited by supply-chain worm, researchers say A supply-chain worm, dubbed Shai-Hulud, is exploiting design flaws in GitHub to infect hundreds of software packages and developer accounts worldwide. The vulnerabilities, initially flagged by Deep Specter Research, were… The Record · Jun 16, 2026 High GBFRsupply chainvulnerabilitygithub
threat-intel North Korean Hackers Are Turning Developer Tools Into Malware Delivery Channels North Korean threat actors, operating under the UNK_DeadDrop campaign, are employing a sophisticated phishing technique targeting developers across numerous sectors, including finance and cryptocurrency, using malicious… The Hacker News · Jun 15, 2026 High USGBAUdevelopergithubvscode
supply-chain Early Warning Signs of Supply-Chain Attacks Live in the Dark Web This BleepingComputer article highlights the increasing threat of supply-chain attacks, which target the tools and vendors organizations rely on. The article details how early warning signs of these attacks often appear… BleepingComputer · Jun 12, 2026 High GEsupply chaingithubcredentials
supply-chain The ‘Miasma’ worm source code briefly leaked on GitHub The source code for the Miasma credential-stealing worm framework, previously linked to supply-chain attacks targeting open-source ecosystems, was briefly leaked on GitHub. This leak, mirroring the earlier Shai-Hulud wor… BleepingComputer · Jun 10, 2026 High USsupply chaincredential theftopen source
supply-chain Miasma Supply Chain Worm Burrows Into 73 Microsoft Repositories A sophisticated supply chain attack, orchestrated by the Miasma worm (a variant of Shai-Hulud), targeted 73 Microsoft GitHub repositories, primarily within the Azure organization. The attack, initially discovered through… Dark Reading · Jun 9, 2026 High supply chaingithubazure