Multiple high-profile open-source projects, including those from Google, Microsoft, AWS, and Red Hat, were found to leak GitHub authentication tokens through GitHub Actions artifacts in CI/CD ...
Researchers have uncovered an attack vector that affected GitHub open source projects owned by Google, Microsoft, Amazon Web Services, and others, executed by abusing artifacts generated as part of ...
GitHub Security Lab's Taskflow Agent found 24 confirmed Android CVEs -- including a zero-permission GPS tracker in OsmAnd and a Wikimedia-wide account takeover in the Wikipedia app -- by guiding an AI ...
The report found the GitHub Actions marketplace’s security posture to be especially concerning, with most custom Actions not verified, maintained by one developer, or generating low-security scores ...
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel.
More than 543,000 working credentials were exposed on GitHub, including thousands published after Push Protection became ...