threat-intel GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures A vulnerability has been discovered in GitHub's signature verification process. Attackers can rewrite signed Git commits, creating new commits with the same content but a different hash, while still appearing as "Verified" to GitHub. This is achieved by manipulating the signature data itself, bypassing traditional hash… The Hacker News · Jul 8, 2026 High gitsignaturevulnerability