Tag GitHub

GitHub Reports Hackers Compromised Multiple Organizations Through Stolen OAuth Access Tokens

GitHub Exposes OAuth Token Exploit Used by Malicious Actor On Friday, GitHub, the prominent cloud-based repository hosting service, announced a breach involving the exploitation of stolen OAuth user tokens by an unidentified adversary. These tokens were allegedly used to illegitimately access and download sensitive data from multiple organizations. Mike Hanley,…

Read MoreGitHub Reports Hackers Compromised Multiple Organizations Through Stolen OAuth Access Tokens

GitHub Alerts Users Whose Private Data Was Compromised via OAuth Tokens

GitHub Confirms Breach Involving Stolen OAuth Tokens GitHub has confirmed a security incident in which unauthorized actors exploited third-party OAuth user tokens from Heroku and Travis CI to access private repository data. On Monday, the platform announced that it has informed all affected customers, emphasizing the need for continued vigilance…

Read MoreGitHub Alerts Users Whose Private Data Was Compromised via OAuth Tokens

GitHub Addresses Critical Vulnerability in Enterprise Server That Permits Unauthorized Access

GitHub Security Updates Address Critical Vulnerabilities in Enterprise Server GitHub has announced crucial security updates for its Enterprise Server (GHES), responding to multiple vulnerabilities, including a severe flaw that could lead to unauthorized access. The updates aim to enhance user protection, particularly against a vulnerability identified as CVE-2024-9487, which has…

Read MoreGitHub Addresses Critical Vulnerability in Enterprise Server That Permits Unauthorized Access

How Hidden Secrets in Source Code Can Cause Major Breaches

The Rise of Supply Chain Attacks: A Growing Concern for Businesses In 2021, the cybersecurity landscape was notably defined by a surge in supply chain attacks. These incidents occur when cybercriminals compromise third-party software components to infiltrate downstream applications. High-profile breaches such as those involving SolarWinds, Kaseya, and Codecov have…

Read MoreHow Hidden Secrets in Source Code Can Cause Major Breaches

Researchers Discover ‘Pink’ Botnet Malware Responsible for Infecting Over 1.6 Million Devices

Recent research has unveiled details of what is being referred to as the largest botnet discovered in the past six years, known as “Pink.” This sophisticated malware has reportedly infected over 1.6 million devices, predominantly located in China. Its primary objectives include orchestrating Distributed Denial-of-Service (DDoS) attacks and injecting ads…

Read MoreResearchers Discover ‘Pink’ Botnet Malware Responsible for Infecting Over 1.6 Million Devices

GlassWorm Malware Targets Developers via OpenVSX Marketplace – Hackread – Your Source for Cybersecurity News, Data Breaches, Tech, AI, Crypto, and More

A recent cyber threat known as GlassWorm has been detected, specifically targeting developers utilizing Visual Studio Code extensions via the OpenVSX marketplace. Koi Security unveiled this campaign, which leverages trusted extensions to automatically propagate across various development environments while employing stolen credentials to facilitate further infections. Distinct from typical malware…

Read MoreGlassWorm Malware Targets Developers via OpenVSX Marketplace – Hackread – Your Source for Cybersecurity News, Data Breaches, Tech, AI, Crypto, and More

Breach Brief: Chinese Hackers Target ArcGIS Vulnerability

Cybercrime, Fraud Management & Cybercrime Internet-Exposed Call Center Software Under Attack; Patch Tuesday Update Anviksha More (AnvikshaMore) • October 16, 2025 Image: Shutterstock/ISMG This week, the Information Security Media Group covers a range of cybersecurity incidents: Chinese hackers exploiting ArcGIS, vulnerabilities in internet-exposed call center software, and the latest Patch…

Read MoreBreach Brief: Chinese Hackers Target ArcGIS Vulnerability

Share Your Secrets Without Revealing Them

The challenge of safeguarding digital secrets in an increasingly interconnected world has become increasingly urgent. GitGuardian’s engineers faced a critical task while developing their HasMySecretLeaked service, designed to assist developers in determining whether confidential information—such as passwords, API keys, and cryptographic certificates—has been inadvertently exposed within public GitHub repositories. The…

Read MoreShare Your Secrets Without Revealing Them

Satellites Exposing Global Secrets: Intercepted Calls, Texts, and Sensitive Military and Corporate Information

Recent findings indicate that individuals around the globe could replicate a sensitive data collection operation, utilizing readily available satellite hardware. Researchers conducted an experiment employing standard satellite technology: a $185 satellite dish, a $140 roof mount, a $195 motor, and a $230 tuner card, all totaling under $800. This highlights…

Read MoreSatellites Exposing Global Secrets: Intercepted Calls, Texts, and Sensitive Military and Corporate Information