Tag: Github

Abdullah Brothers & Co. has onboarded FlowHCM to enhance HR operations through a connected platform designed to support workforce management and business growth.
Microtech Inc. has received the Authorized Distributor Certificate from ZKTeco Inc., strengthening their partnership to expand security and smart technology solutions.

GitHub Introduces Three Day Dependabot Delay To Reduce Supply Chain Risks

GitHub has introduced a default three day cooldown for Dependabot version updates to help reduce the risk of poisoned software packages spreading through supply chains.

Thousands Of Malicious GitHub Repositories Distribute SmartLoader Malware Through AI Lures

Researchers have uncovered the FakeGit campaign using nearly 7,600 malicious GitHub repositories, including AI skills and MCP servers, to distribute SmartLoader and StealC malware.

North Korea Linked npm Packages Impersonate Rollup Polyfill Tools To Target Developer Systems And Steal Secrets

Security researchers have uncovered malicious npm packages linked to North Korea that impersonate Rollup polyfill tools to deliver remote access malware and steal developer credentials and sensitive data.

GuardFall Research Reveals Shell Injection Risks Across Open Source AI Coding Agents

Adversa AI has disclosed GuardFall, a shell injection bypass affecting 10 of 11 tested open source AI coding agents, exposing systems to command execution and credential theft risks.

GitHub Strengthens Actions Security With Checkout Update to Block Pwn Request Attacks

GitHub has updated actions/checkout to block common pwn request attack patterns by default, helping protect repositories from software supply chain threats linked to pull_request_target workflows.

Anthropic Accidentally Exposes Part Of Claude Code Source Files

Anthropic releases nearly 2,000 files and 500,000 lines of Claude Code source code by mistake, clarifying no sensitive data was affected.

Malicious Go Crypto Module Steals Passwords And Deploys Rekoobe Backdoor On Linux Systems

Researchers uncover a malicious Go module impersonating golang.org/x/crypto that steals terminal passwords, installs SSH persistence, and deploys the Rekoobe Linux backdoor.

Recent articles

spot_img