Skip to main content
← All Articles

Tag

#GitHub

52 articles

Advertisement

HIGH
Cloud Security

CISA Contractor Leaks AWS GovCloud Credentials via GitHub Repository

A significant security leak involving a CISA contractor has exposed privileged AWS GovCloud credentials and internal software deployment processes on GitHub.

Runtime Rebel Intel
4 min read · May 23, 2026
HIGH
Data Breach

CISA Data Leak: AWS GovCloud Keys Exposed via Public GitHub Repo

Lawmakers demand answers from CISA after a contractor leaked AWS GovCloud keys and internal secrets on GitHub, prompting urgent credential rotation.

Runtime Rebel Intel
4 min read · May 22, 2026
GitHub Data Breach: Analysis of TeamPCP Internal Repository Theft
HIGH
Data Breach

GitHub Data Breach: Analysis of TeamPCP Internal Repository Theft

GitHub confirms the theft of 4,000 internal repositories by threat actor TeamPCP. Learn the technical implications and defense strategies for security teams.

Runtime Rebel Intel
3 min read · May 21, 2026
HIGH
Supply Chain

GitHub Repository Breach Linked to TanStack Supply Chain Attack

GitHub confirms the breach of 3,800 internal repositories via a compromised VS Code extension linked to the TanStack npm supply chain attack.

Runtime Rebel Intel
4 min read · May 21, 2026
GitHub Internal Repositories Breached via Nx Console VS Code Extension
MEDIUM
Supply Chain

GitHub Internal Repositories Breached via Nx Console VS Code Extension

GitHub confirms internal repository breach after an employee device was compromised by a poisoned Nx Console VS Code extension in a supply chain attack.

Runtime Rebel Intel
3 min read · May 21, 2026
HIGH
Supply Chain

GitHub Repository Breach: 3,800 Repos Accessed via VS Code Extension

GitHub confirms a security incident where a malicious VS Code extension compromised an employee account, leading to the unauthorized access of 3,800 repos.

Runtime Rebel Intel
4 min read · May 20, 2026

Advertisement

HIGH
Data Breach

GitHub Internal Repo Breach Claimed by TeamPCP – Code at Risk

GitHub investigates TeamPCP's claim of breaching internal repositories, potentially exposing 4,000 private codebases. Defenders must secure supply chains.

Runtime Rebel Intel
5 min read · May 20, 2026
GitHub Investigates Claimed TeamPCP Breach of 4,000 Internal Repos
HIGH
Data Breach

GitHub Investigates Claimed TeamPCP Breach of 4,000 Internal Repos

GitHub is investigating a potential breach of 4,000 internal repositories claimed by TeamPCP, highlighting the risk of source code leaks for enterprises.

Runtime Rebel Intel
4 min read · May 20, 2026
CISA GitHub Repo Exposes Secrets & Credentials in Public View
HIGH
Cloud Security

CISA GitHub Repo Exposes Secrets & Credentials in Public View

CISA inadvertently exposed sensitive secrets and credentials within a publicly accessible GitHub repository.

Runtime Rebel Intel
5 min read · May 19, 2026
HIGH
Cloud Security

CISA Contractor Leaked AWS GovCloud Keys on GitHub: Critical Exposure

A CISA contractor publicly exposed highly privileged AWS GovCloud and internal system credentials on GitHub, detailing CISA's software development.

Runtime Rebel Intel
5 min read · May 19, 2026
HIGH
Supply Chain

Grafana GitHub Token Compromise: Codebase Stolen via PAT

Grafana Labs reports a source code breach after attackers leveraged a stolen GitHub Personal Access Token. Analysis of the impact and mitigation steps.

Runtime Rebel Intel
3 min read · May 18, 2026
Grafana GitHub Token Leak: Codebase Access and Extortion Attempt
HIGH
Supply Chain

Grafana GitHub Token Leak: Codebase Access and Extortion Attempt

Grafana discloses a security incident where an unauthorized party used a GitHub token to download source code, leading to a failed extortion attempt.

Runtime Rebel Intel
3 min read · May 17, 2026
GitHub High-Severity Bug Discovered via AI Reverse Engineering
HIGH
Vulnerabilities

GitHub High-Severity Bug Discovered via AI Reverse Engineering

Wiz utilized AI reverse-engineering to uncover a high-severity vulnerability within GitHub, demonstrating advanced discovery methods for complex bugs.

Runtime Rebel Intel
4 min read · Apr 29, 2026
HIGH
Supply Chain

Checkmarx Supply Chain Attack: GitHub Data Exfiltration Confirmed

Checkmarx confirms data exfiltration from its GitHub environment following a malicious code publication. Learn about the TTPs and mitigation strategies.

Runtime Rebel Intel
4 min read · Apr 29, 2026
CVE-2026-3854: GitHub RCE via Malicious Git Push Command
HIGH
Vulnerabilities

CVE-2026-3854: GitHub RCE via Malicious Git Push Command

A critical command injection vulnerability, CVE-2026-3854, allows authenticated users to achieve RCE on GitHub instances via a single git push operation.

Runtime Rebel Intel
3 min read · Apr 28, 2026
Checkmarx GitHub Repository Data Leaked Following Supply Chain Attack
HIGH
Supply Chain

Checkmarx GitHub Repository Data Leaked Following Supply Chain Attack

Checkmarx confirms internal GitHub repository data was published on the dark web following a March 2026 supply chain incident. Learn the impact and TTPs.

Runtime Rebel Intel
4 min read · Apr 27, 2026
AI-Assisted Supply Chain Attack Targets GitHub Misconfigurations
MEDIUM
Supply Chain

AI-Assisted Supply Chain Attack Targets GitHub Misconfigurations

Analysis of the AI-assisted PRT-scan supply chain attack targeting GitHub misconfigurations. Learn about automated threats and securing repositories.

Runtime Rebel Intel
4 min read · Apr 7, 2026
HIGH
Malware

Fake GitHub Repositories Deliver Vidar Infostealer via Claude Leak

Threat actors are exploiting the Claude Code leak, deploying fake GitHub repositories to distribute Vidar infostealer malware, targeting unsuspecting developers and…

Runtime Rebel Intel
4 min read · Apr 3, 2026
HIGH
Identity & Access

OpenAI Codex Vulnerability Exposed GitHub Tokens via OAuth Flaw

Researchers discovered a critical OpenAI Codex vulnerability allowing GitHub token theft via OAuth flaws, risking unauthorized access to private repositories.

Runtime Rebel Intel
4 min read · Mar 31, 2026
OpenAI Patches ChatGPT Data Exfiltration and Codex Token Flaws
HIGH
Vulnerabilities

OpenAI Patches ChatGPT Data Exfiltration and Codex Token Flaws

OpenAI addresses high-impact vulnerabilities in ChatGPT and Codex that enabled unauthorized data exfiltration and exposure of sensitive GitHub tokens.

Runtime Rebel Intel
3 min read · Mar 30, 2026
GitGuardian 2026 Report: Analyzing the 34% Surge in Secrets Sprawl
MEDIUM
Identity & Access

GitGuardian 2026 Report: Analyzing the 34% Surge in Secrets Sprawl

GitGuardian's 2026 report reveals 29 million leaked secrets on GitHub in 2025. Learn how AI and hardcoded credentials impact enterprise security posture.

Runtime Rebel Intel
4 min read · Mar 30, 2026
HIGH
Threat Intel

GitHub Malware Campaign: Fake VS Code Alerts Target Developers

Attackers exploit GitHub Discussions to push malware via fake VS Code security alerts. Learn the TTPs used to target developers and how to mitigate risk.

Runtime Rebel Intel
4 min read · Mar 27, 2026
INFO
Vulnerabilities

GitHub Copilot Autofix: AI-Driven Vulnerability Remediation in GHAS

GitHub integrates AI-powered scanning into Advanced Security to detect and remediate vulnerabilities across more languages using Copilot Autofix.

Runtime Rebel Intel
3 min read · Mar 26, 2026
Malicious GitHub OpenClaw Deployer Repos Deliver Trojans
HIGH
Supply Chain

Malicious GitHub OpenClaw Deployer Repos Deliver Trojans

Analysts uncover an AI-assisted campaign using over 300 poisoned GitHub repositories like OpenClaw Deployer to distribute infostealers to developers.

Runtime Rebel Intel
4 min read · Mar 24, 2026