Skip to main content
← All Articles

Tag

#GitHub

33 articles

Advertisement

AI-Assisted Supply Chain Attack Targets GitHub Misconfigurations
HIGH
Supply Chain

AI-Assisted Supply Chain Attack Targets GitHub Misconfigurations

Analysis of the AI-assisted PRT-scan supply chain attack targeting GitHub misconfigurations. Learn about automated threats and securing repositories.

Runtime Rebel Intel
4 min read·Apr 7, 2026
MA
HIGH
Malware

Fake GitHub Repositories Deliver Vidar Infostealer via Claude Leak

Threat actors are exploiting the Claude Code leak, deploying fake GitHub repositories to distribute Vidar infostealer malware, targeting unsuspecting developers and

Runtime Rebel Intel
4 min read·Apr 3, 2026
ID
HIGH
Identity & Access

OpenAI Codex Vulnerability Exposed GitHub Tokens via OAuth Flaw

Researchers discovered a critical OpenAI Codex vulnerability allowing GitHub token theft via OAuth flaws, risking unauthorized access to private repositories.

Runtime Rebel Intel
4 min read·Mar 31, 2026
OpenAI Patches ChatGPT Data Exfiltration and Codex Token Flaws
HIGH
Vulnerabilities

OpenAI Patches ChatGPT Data Exfiltration and Codex Token Flaws

OpenAI addresses high-impact vulnerabilities in ChatGPT and Codex that enabled unauthorized data exfiltration and exposure of sensitive GitHub tokens.

Runtime Rebel Intel
3 min read·Mar 30, 2026
GitGuardian 2026 Report: Analyzing the 34% Surge in Secrets Sprawl
HIGH
Identity & Access

GitGuardian 2026 Report: Analyzing the 34% Surge in Secrets Sprawl

GitGuardian's 2026 report reveals 29 million leaked secrets on GitHub in 2025. Learn how AI and hardcoded credentials impact enterprise security posture.

Runtime Rebel Intel
3 min read·Mar 30, 2026
SU
HIGH
Supply Chain

ForceMemo: Credential Theft Compromises Python Repositories

Researchers reveal ForceMemo, a campaign exploiting credentials stolen via GlassWorm to compromise hundreds of GitHub accounts and Python repositories.

Runtime Rebel Intel
3 min read·Mar 16, 2026
SU
HIGH
Supply Chain

Over 100 GitHub Repositories Distributing BoryptGrab Stealer

A large-scale campaign on GitHub utilizes over 100 repositories to distribute BoryptGrab, an info-stealer targeting crypto wallets and browser data.

Runtime Rebel Intel
3 min read·Mar 7, 2026
MA
HIGH
Malware

Bing AI Promotes Fake GitHub Repositories Spreading Info-Stealers

Microsoft Bing AI search promoted malicious GitHub repositories hosting fake OpenClaw software, leading to info-stealing and proxy malware deployment.

Runtime Rebel Intel
4 min read·Mar 6, 2026
Microsoft Warns of Fake Next.js Repos Delivering In-Memory Malware
HIGH
Threat Intel

Microsoft Warns of Fake Next.js Repos Delivering In-Memory Malware

Microsoft warns developers of a coordinated campaign using malicious Next.js repositories disguised as job assessments to deliver in-memory malware.

Runtime Rebel Intel
3 min read·Feb 26, 2026