<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #GitHub</title><description>Cybersecurity articles tagged #GitHub on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>TeamPCP Hackers Arrested in Australia Over Supply Chain Attacks</title><link>https://runtimerebel.com/blog/teampcp-hackers-arrested-in-australia-over-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-hackers-arrested-in-australia-over-supply-chain-attacks</guid><description>Australian Federal Police arrest two men linked to TeamPCP, a cybercrime syndicate behind major software supply chain attacks and data extortion.</description><pubDate>Tue, 01 Sep 2026 02:41:36 GMT</pubDate><category>TeamPCP</category><category>Supply Chain Attack</category><category>Shai Hulud</category><category>GitHub</category><category>LiteLLM</category></item><item><title>GitHub and PyPI Policy Updates Target Supply Chain Security</title><link>https://runtimerebel.com/blog/github-and-pypi-policy-updates-target-supply-chain-security</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-and-pypi-policy-updates-target-supply-chain-security</guid><description>GitHub and PyPI introduce new restrictions to thwart supply chain attacks, including a Dependabot cooldown and limits on historical package file uploads.</description><pubDate>Mon, 27 Jul 2026 14:40:00 GMT</pubDate><category>GitHub</category><category>PyPI</category><category>Supply Chain Security</category><category>Dependabot</category><category>Open Source</category></item><item><title>GitHub Dependabot 3-Day Cooldown: Mitigating Supply Chain Attacks</title><link>https://runtimerebel.com/blog/github-dependabot-3-day-cooldown-mitigating-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-dependabot-3-day-cooldown-mitigating-supply-chain-attacks</guid><description>GitHub introduces a 3-day cooldown for Dependabot to prevent the rapid adoption of malicious packages, enhancing supply chain security for developers.</description><pubDate>Mon, 27 Jul 2026 11:25:20 GMT</pubDate><category>GitHub</category><category>Dependabot</category><category>Supply Chain Security</category><category>Malicious Packages</category><category>Open Source</category></item><item><title>GitHub and PyPI Time-Based Defenses Against Supply Chain Attacks</title><link>https://runtimerebel.com/blog/github-and-pypi-time-based-defenses-against-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-and-pypi-time-based-defenses-against-supply-chain-attacks</guid><description>GitHub and PyPI introduce time-based delays in Dependabot to mitigate supply chain attacks by preventing the immediate ingestion of malicious packages.</description><pubDate>Sun, 26 Jul 2026 17:03:02 GMT</pubDate><category>GitHub</category><category>PyPI</category><category>Dependabot</category><category>Supply Chain Security</category><category>Python</category></item><item><title>GitHub Adjusts Bug Bounty: Impact on Vulnerability Disclosure</title><link>https://runtimerebel.com/blog/github-adjusts-bug-bounty-impact-on-vulnerability-disclosure</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-adjusts-bug-bounty-impact-on-vulnerability-disclosure</guid><description>GitHub is halving public bug bounty payouts and shifting top rewards to an invite-only VIP program, impacting vulnerability research and disclosure.</description><pubDate>Wed, 22 Jul 2026 21:11:24 GMT</pubDate><category>GitHub</category><category>Bug Bounty</category><category>Vulnerability Disclosure</category><category>Security Research</category><category>Software Supply Chain</category></item><item><title>FakeGit Campaign Leverages 7,600 GitHub Repos to Distribute SmartLoader, StealC</title><link>https://runtimerebel.com/blog/fakegit-campaign-leverages-7600-github-repos-to-distribute-smartloader-stealc</link><guid isPermaLink="true">https://runtimerebel.com/blog/fakegit-campaign-leverages-7600-github-repos-to-distribute-smartloader-stealc</guid><description>Analysis of the FakeGit campaign distributing SmartLoader and StealC malware via over 7,600 deceptive GitHub repositories, impacting millions of downloads.</description><pubDate>Wed, 22 Jul 2026 02:46:33 GMT</pubDate><category>FakeGit</category><category>SmartLoader</category><category>StealC</category><category>GitHub</category><category>Supply Chain Attack</category><category>Typosquatting</category><category>Malware Distribution</category></item><item><title>FakeGit Campaign Exploits GitHub for SmartLoader Malware</title><link>https://runtimerebel.com/blog/fakegit-campaign-exploits-github-for-smartloader-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/fakegit-campaign-exploits-github-for-smartloader-malware</guid><description>Analysis of the FakeGit campaign leveraging 7,600 GitHub repositories, including AI/MCP lures, to distribute SmartLoader malware. Learn detection and mitigation.</description><pubDate>Mon, 20 Jul 2026 21:13:10 GMT</pubDate><category>FakeGit</category><category>SmartLoader</category><category>GitHub</category><category>Malware</category><category>Supply Chain Attack</category><category>Social Engineering</category><category>Software Supply Chain</category></item><item><title>Malicious GitHub Repositories: Infostealer Distribution Threat</title><link>https://runtimerebel.com/blog/malicious-github-repositories-infostealer-distribution-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-github-repositories-infostealer-distribution-threat</guid><description>Threat actors are leveraging nearly 300 fake GitHub repositories, impersonating legitimate software, to distribute infostealer malware.</description><pubDate>Tue, 14 Jul 2026 21:03:07 GMT</pubDate><category>GitHub</category><category>Infostealer</category><category>Malware Distribution</category><category>Supply Chain Attack</category><category>Software Impersonation</category></item><item><title>CISA GitHub Leak: Lessons from AWS Govcloud Credential Exposure</title><link>https://runtimerebel.com/blog/cisa-github-leak-lessons-from-aws-govcloud-credential-exposure</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-github-leak-lessons-from-aws-govcloud-credential-exposure</guid><description>Analysis of CISA&apos;s recent GitHub leak, detailing the exposure of AWS Govcloud keys and internal credentials, and providing critical lessons for cloud security.</description><pubDate>Mon, 13 Jul 2026 17:59:58 GMT</pubDate><category>CISA</category><category>GitHub</category><category>AWS GovCloud</category><category>Data Leak</category><category>Cloud Security</category><category>Credential Exposure</category><category>Secrets Management</category></item><item><title>GitHub API Abuse: Detecting Ghost Account Reconnaissance Campaigns</title><link>https://runtimerebel.com/blog/github-api-abuse-detecting-ghost-account-reconnaissance-campaigns</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-api-abuse-detecting-ghost-account-reconnaissance-campaigns</guid><description>Threat actors are leveraging thousands of ghost accounts to map GitHub organizations via API abuse, facilitating future targeted supply chain attacks.</description><pubDate>Sat, 11 Jul 2026 20:51:29 GMT</pubDate><category>GitHub</category><category>API Security</category><category>Reconnaissance</category><category>Ghost Accounts</category></item><item><title>GitHub API Abuse: Attackers Map Corporate Orgs via Dormant Accounts</title><link>https://runtimerebel.com/blog/github-api-abuse-attackers-map-corporate-orgs-via-dormant-accounts</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-api-abuse-attackers-map-corporate-orgs-via-dormant-accounts</guid><description>Datadog Security Labs warns of systematic GitHub API enumeration campaigns using dormant accounts and compromised OAuth tokens to map corporate organizations.</description><pubDate>Thu, 09 Jul 2026 21:25:09 GMT</pubDate><category>GitHub</category><category>API Abuse</category><category>Reconnaissance</category><category>OAuth Token</category><category>Supply Chain</category><category>Datadog</category></item><item><title>Cordyceps CI/CD Flaws: Supply Chain Attacks on GitHub Repositories</title><link>https://runtimerebel.com/blog/cordyceps-ci-cd-flaws-supply-chain-attacks-on-github-repositories</link><guid isPermaLink="true">https://runtimerebel.com/blog/cordyceps-ci-cd-flaws-supply-chain-attacks-on-github-repositories</guid><description>Novee Security uncovered Cordyceps, a critical CI/CD workflow flaw exposing over 300 GitHub repositories to supply chain compromise, affecting major organizations.</description><pubDate>Wed, 24 Jun 2026 16:50:14 GMT</pubDate><category>Cordyceps</category><category>CI CD</category><category>GitHub</category><category>Supply Chain Attack</category><category>Novee Security</category><category>Repository Compromise</category></item><item><title>Novo Nordisk Breach: Securing Secrets in GitHub Development Pipelines</title><link>https://runtimerebel.com/blog/novo-nordisk-breach-securing-secrets-in-github-development-pipelines</link><guid isPermaLink="true">https://runtimerebel.com/blog/novo-nordisk-breach-securing-secrets-in-github-development-pipelines</guid><description>Analysis of the Novo Nordisk GitHub token leak and why secrets management must transition from static tools to identity-based security frameworks.</description><pubDate>Fri, 19 Jun 2026 09:48:31 GMT</pubDate><category>GitHub</category><category>Secrets Management</category><category>Novo Nordisk</category><category>DevSecOps</category><category>CI CD Security</category></item><item><title>GitHub to Disable npm Install Scripts by Default in Version 12</title><link>https://runtimerebel.com/blog/github-to-disable-npm-install-scripts-by-default-in-version-12</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-to-disable-npm-install-scripts-by-default-in-version-12</guid><description>GitHub announces breaking changes for npm v12, disabling install scripts by default to prevent malicious code execution and enhance supply chain security.</description><pubDate>Thu, 11 Jun 2026 09:37:20 GMT</pubDate><category>NPM</category><category>GitHub</category><category>Npm V12</category><category>Supply Chain Security</category><category>Malware Prevention</category></item><item><title>Miasma Worm Source Code Briefly Leaked on GitHub</title><link>https://runtimerebel.com/blog/miasma-worm-source-code-briefly-leaked-on-github</link><guid isPermaLink="true">https://runtimerebel.com/blog/miasma-worm-source-code-briefly-leaked-on-github</guid><description>Analysis of the Miasma worm source code leak on GitHub, a credential-stealing framework targeting open-source ecosystems via supply-chain attacks.</description><pubDate>Wed, 10 Jun 2026 20:58:55 GMT</pubDate><category>Miasma</category><category>Worm</category><category>Credential Stealing</category><category>Supply Chain Attack</category><category>GitHub</category><category>Open Source Security</category></item><item><title>GitHub Supply Chain Disruption: Microsoft Repos Abused to Host Malware</title><link>https://runtimerebel.com/blog/github-supply-chain-disruption-microsoft-repos-abused-to-host-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-supply-chain-disruption-microsoft-repos-abused-to-host-malware</guid><description>GitHub recently disabled 73 official Microsoft repositories after they were targeted in a massive campaign pushing password-stealing malware to developers.</description><pubDate>Tue, 09 Jun 2026 17:00:46 GMT</pubDate><category>GitHub</category><category>Microsoft</category><category>Supply Chain Attack</category><category>Infostealer</category><category>DevSecOps</category></item><item><title>Miasma Compromises 73 Microsoft GitHub Repos: Incident Analysis</title><link>https://runtimerebel.com/blog/miasma-compromises-73-microsoft-github-repos-incident-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/miasma-compromises-73-microsoft-github-repos-incident-analysis</guid><description>Microsoft restores some GitHub repositories after 73 projects were hit by Miasma&apos;s supply chain attack to inject information stealers. Learn detection steps.</description><pubDate>Tue, 09 Jun 2026 17:00:07 GMT</pubDate><category>GitHub</category><category>Miasma</category><category>Microsoft</category><category>Supply Chain Attack</category><category>Information Stealer</category><category>Open Source Security</category></item><item><title>VS Code One-Click GitHub Token Theft via URI Handler Exploitation</title><link>https://runtimerebel.com/blog/vs-code-one-click-github-token-theft-via-uri-handler-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/vs-code-one-click-github-token-theft-via-uri-handler-exploitation</guid><description>A flaw in Visual Studio Code allows attackers to steal GitHub authentication tokens with a single click. Learn the technical details and mitigation steps.</description><pubDate>Thu, 04 Jun 2026 09:26:58 GMT</pubDate><category>Visual Studio Code</category><category>GitHub</category><category>Token Theft</category><category>URI Handler</category><category>Social Engineering</category></item><item><title>GitHub.dev One-Click Attack: Stealing OAuth Tokens via VS Code</title><link>https://runtimerebel.com/blog/github-dev-one-click-attack-stealing-oauth-tokens-via-vs-code</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-dev-one-click-attack-stealing-oauth-tokens-via-vs-code</guid><description>New research reveals a one-click exploit in GitHub.dev and VS Code that allows attackers to steal full GitHub OAuth tokens and access private repositories.</description><pubDate>Wed, 03 Jun 2026 13:47:14 GMT</pubDate><category>GitHub</category><category>VS Code</category><category>Oauth Theft</category><category>URI Handler</category></item><item><title>Megalodon Malware: GitHub Repo Compromise &amp; Secret Theft</title><link>https://runtimerebel.com/blog/megalodon-malware-github-repo-compromise-secret-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/megalodon-malware-github-repo-compromise-secret-theft</guid><description>Analysis of the Megalodon malware campaign, which compromised over 5,500 GitHub repositories in six hours to steal developer credentials and sensitive secrets.</description><pubDate>Tue, 26 May 2026 20:47:15 GMT</pubDate><category>Megalodon Malware</category><category>GitHub</category><category>Supply Chain Attack</category><category>Developer Secrets</category><category>Credential Theft</category><category>Repository Compromise</category></item><item><title>TeamPCP Supply Chain Attack Targets Microsoft SDKs and GitHub</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-attack-targets-microsoft-sdks-and-github</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-attack-targets-microsoft-sdks-and-github</guid><description>TeamPCP expands its supply chain campaign to trojanize official Microsoft Python SDKs and infiltrate GitHub, requiring immediate dependency audits.</description><pubDate>Mon, 25 May 2026 16:52:00 GMT</pubDate><category>TeamPCP</category><category>Supply Chain Attack</category><category>Python SDK</category><category>GitHub</category><category>PyPI</category><category>NPM</category></item><item><title>Megalodon Supply Chain Attack Infects 5,500+ GitHub Repositories</title><link>https://runtimerebel.com/blog/megalodon-supply-chain-attack-infects-5500-github-repositories</link><guid isPermaLink="true">https://runtimerebel.com/blog/megalodon-supply-chain-attack-infects-5500-github-repositories</guid><description>Attackers used automated commits to inject malicious GitHub Actions workflows into 5,500+ repositories, targeting CI/CD secrets and sensitive tokens.</description><pubDate>Mon, 25 May 2026 09:28:56 GMT</pubDate><category>GitHub</category><category>Supply Chain Attack</category><category>Megalodon</category><category>GitHub Actions</category><category>Credential Theft</category></item><item><title>Packagist Supply Chain Attack: 8 Packages Deliver Linux Malware</title><link>https://runtimerebel.com/blog/packagist-supply-chain-attack-8-packages-deliver-linux-malware</link><guid isPermaLink="true">https://runtimerebel.com/blog/packagist-supply-chain-attack-8-packages-deliver-linux-malware</guid><description>Security researchers identified a supply chain attack on Packagist involving eight infected packages that deploy Linux malware via GitHub Releases URLs.</description><pubDate>Sat, 23 May 2026 20:22:18 GMT</pubDate><category>Packagist</category><category>Composer</category><category>Linux Malware</category><category>Supply Chain Attack</category><category>GitHub</category></item><item><title>npm Staged Publishing: New 2FA Controls Prevent Supply Chain Attacks</title><link>https://runtimerebel.com/blog/npm-staged-publishing-new-2fa-controls-prevent-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/npm-staged-publishing-new-2fa-controls-prevent-supply-chain-attacks</guid><description>GitHub introduces staged publishing for npm, requiring manual 2FA approval for package releases to mitigate malicious automated updates and account takeovers.</description><pubDate>Sat, 23 May 2026 20:21:54 GMT</pubDate><category>NPM</category><category>GitHub</category><category>Supply Chain Security</category><category>Two Factor Authentication</category><category>Staged Publishing</category><category>Application Security</category></item><item><title>CISA Contractor Leaks AWS GovCloud Credentials via GitHub Repository</title><link>https://runtimerebel.com/blog/cisa-contractor-leaks-aws-govcloud-credentials-via-github-repository</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-contractor-leaks-aws-govcloud-credentials-via-github-repository</guid><description>A significant security leak involving a CISA contractor has exposed privileged AWS GovCloud credentials and internal software deployment processes on GitHub.</description><pubDate>Sat, 23 May 2026 00:55:30 GMT</pubDate><category>CISA</category><category>AWS GovCloud</category><category>GitHub</category><category>Credential Leak</category><category>Supply Chain</category></item><item><title>CISA Data Leak: AWS GovCloud Keys Exposed via Public GitHub Repo</title><link>https://runtimerebel.com/blog/cisa-data-leak-aws-govcloud-keys-exposed-via-public-github-repo</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-data-leak-aws-govcloud-keys-exposed-via-public-github-repo</guid><description>Lawmakers demand answers from CISA after a contractor leaked AWS GovCloud keys and internal secrets on GitHub, prompting urgent credential rotation.</description><pubDate>Fri, 22 May 2026 16:50:37 GMT</pubDate><category>CISA</category><category>AWS GovCloud</category><category>GitHub</category><category>Credential Exposure</category><category>Insider Threat</category></item><item><title>GitHub Data Breach: Analysis of TeamPCP Internal Repository Theft</title><link>https://runtimerebel.com/blog/github-data-breach-analysis-of-teampcp-internal-repository-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-data-breach-analysis-of-teampcp-internal-repository-theft</guid><description>GitHub confirms the theft of 4,000 internal repositories by threat actor TeamPCP. Learn the technical implications and defense strategies for security teams.</description><pubDate>Thu, 21 May 2026 09:16:24 GMT</pubDate><category>GitHub</category><category>TeamPCP</category><category>Source Code Theft</category><category>Internal Repositories</category><category>Data Exfiltration</category></item><item><title>GitHub Repository Breach Linked to TanStack Supply Chain Attack</title><link>https://runtimerebel.com/blog/github-repository-breach-linked-to-tanstack-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-repository-breach-linked-to-tanstack-supply-chain-attack</guid><description>GitHub confirms the breach of 3,800 internal repositories via a compromised VS Code extension linked to the TanStack npm supply chain attack.</description><pubDate>Thu, 21 May 2026 09:15:44 GMT</pubDate><category>GitHub</category><category>TanStack</category><category>NPM</category><category>Supply Chain Attack</category><category>VS Code</category></item><item><title>GitHub Internal Repositories Breached via Nx Console VS Code Extension</title><link>https://runtimerebel.com/blog/github-internal-repositories-breached-via-nx-console-vs-code-extension</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-internal-repositories-breached-via-nx-console-vs-code-extension</guid><description>GitHub confirms internal repository breach after an employee device was compromised by a poisoned Nx Console VS Code extension in a supply chain attack.</description><pubDate>Thu, 21 May 2026 05:31:21 GMT</pubDate><category>GitHub</category><category>Nx Console</category><category>Vscode Extensions</category><category>Supply Chain Attack</category><category>Nrwl Angular Console</category></item><item><title>GitHub Repository Breach: 3,800 Repos Accessed via VS Code Extension</title><link>https://runtimerebel.com/blog/github-repository-breach-3800-repos-accessed-via-vs-code-extension</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-repository-breach-3800-repos-accessed-via-vs-code-extension</guid><description>GitHub confirms a security incident where a malicious VS Code extension compromised an employee account, leading to the unauthorized access of 3,800 repos.</description><pubDate>Wed, 20 May 2026 09:15:55 GMT</pubDate><category>GitHub</category><category>VS Code</category><category>Supply Chain Attack</category><category>Credential Theft</category><category>Developer Security</category></item><item><title>GitHub Internal Repo Breach Claimed by TeamPCP – Code at Risk</title><link>https://runtimerebel.com/blog/github-internal-repo-breach-claimed-by-teampcp-code-at-risk</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-internal-repo-breach-claimed-by-teampcp-code-at-risk</guid><description>GitHub investigates TeamPCP&apos;s claim of breaching internal repositories, potentially exposing 4,000 private codebases. Defenders must secure supply chains.</description><pubDate>Wed, 20 May 2026 05:27:49 GMT</pubDate><category>GitHub</category><category>TeamPCP</category><category>Data Breach</category><category>Supply Chain</category><category>Source Code</category></item><item><title>GitHub Investigates Claimed TeamPCP Breach of 4,000 Internal Repos</title><link>https://runtimerebel.com/blog/github-investigates-claimed-teampcp-breach-of-4000-internal-repos</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-investigates-claimed-teampcp-breach-of-4000-internal-repos</guid><description>GitHub is investigating a potential breach of 4,000 internal repositories claimed by TeamPCP, highlighting the risk of source code leaks for enterprises.</description><pubDate>Wed, 20 May 2026 05:27:11 GMT</pubDate><category>GitHub</category><category>TeamPCP</category><category>Source Code Leak</category><category>Data Breach</category><category>Cybercrime</category></item><item><title>CISA GitHub Repo Exposes Secrets &amp; Credentials in Public View</title><link>https://runtimerebel.com/blog/cisa-github-repo-exposes-secrets-credentials-in-public-view</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-github-repo-exposes-secrets-credentials-in-public-view</guid><description>CISA inadvertently exposed sensitive secrets and credentials within a publicly accessible GitHub repository.</description><pubDate>Tue, 19 May 2026 20:42:19 GMT</pubDate><category>CISA</category><category>GitHub</category><category>Data Exposure</category><category>Credentials</category><category>Secrets Management</category><category>Cloud Security Misconfiguration</category></item><item><title>CISA Contractor Leaked AWS GovCloud Keys on GitHub: Critical Exposure</title><link>https://runtimerebel.com/blog/cisa-contractor-leaked-aws-govcloud-keys-on-github-critical-exposure</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisa-contractor-leaked-aws-govcloud-keys-on-github-critical-exposure</guid><description>A CISA contractor publicly exposed highly privileged AWS GovCloud and internal system credentials on GitHub, detailing CISA&apos;s software development.</description><pubDate>Tue, 19 May 2026 00:57:26 GMT</pubDate><category>CISA</category><category>AWS GovCloud</category><category>GitHub</category><category>Data Leak</category><category>Credentials</category><category>Government Security</category><category>Supply Chain</category></item><item><title>Grafana GitHub Token Compromise: Codebase Stolen via PAT</title><link>https://runtimerebel.com/blog/grafana-github-token-compromise-codebase-stolen-via-pat</link><guid isPermaLink="true">https://runtimerebel.com/blog/grafana-github-token-compromise-codebase-stolen-via-pat</guid><description>Grafana Labs reports a source code breach after attackers leveraged a stolen GitHub Personal Access Token. Analysis of the impact and mitigation steps.</description><pubDate>Mon, 18 May 2026 17:03:57 GMT</pubDate><category>Grafana</category><category>GitHub</category><category>Credential Theft</category><category>Source Code Exfiltration</category><category>Supply Chain Security</category></item><item><title>Grafana GitHub Token Leak: Codebase Access and Extortion Attempt</title><link>https://runtimerebel.com/blog/grafana-github-token-leak-codebase-access-and-extortion-attempt</link><guid isPermaLink="true">https://runtimerebel.com/blog/grafana-github-token-leak-codebase-access-and-extortion-attempt</guid><description>Grafana discloses a security incident where an unauthorized party used a GitHub token to download source code, leading to a failed extortion attempt.</description><pubDate>Sun, 17 May 2026 08:48:24 GMT</pubDate><category>Grafana</category><category>GitHub</category><category>Token Leak</category><category>Codebase Theft</category><category>Extortion</category></item><item><title>GitHub High-Severity Bug Discovered via AI Reverse Engineering</title><link>https://runtimerebel.com/blog/github-high-severity-bug-discovered-via-ai-reverse-engineering</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-high-severity-bug-discovered-via-ai-reverse-engineering</guid><description>Wiz utilized AI reverse-engineering to uncover a high-severity vulnerability within GitHub, demonstrating advanced discovery methods for complex bugs.</description><pubDate>Wed, 29 Apr 2026 20:32:08 GMT</pubDate><category>GitHub</category><category>Application Security</category><category>AI in Security</category><category>Vulnerability Discovery</category><category>Reverse Engineering</category><category>Wiz</category></item><item><title>Checkmarx Supply Chain Attack: GitHub Data Exfiltration Confirmed</title><link>https://runtimerebel.com/blog/checkmarx-supply-chain-attack-github-data-exfiltration-confirmed</link><guid isPermaLink="true">https://runtimerebel.com/blog/checkmarx-supply-chain-attack-github-data-exfiltration-confirmed</guid><description>Checkmarx confirms data exfiltration from its GitHub environment following a malicious code publication. Learn about the TTPs and mitigation strategies.</description><pubDate>Wed, 29 Apr 2026 12:42:21 GMT</pubDate><category>Checkmarx</category><category>GitHub</category><category>Supply Chain Attack</category><category>Data Breach</category><category>Malicious Packages</category></item><item><title>CVE-2026-3854: GitHub RCE via Malicious Git Push Command</title><link>https://runtimerebel.com/blog/cve-2026-3854-github-rce-via-malicious-git-push-command</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-3854-github-rce-via-malicious-git-push-command</guid><description>A critical command injection vulnerability, CVE-2026-3854, allows authenticated users to achieve RCE on GitHub instances via a single git push operation.</description><pubDate>Tue, 28 Apr 2026 20:33:48 GMT</pubDate><category>CVE-2026-3854</category><category>GitHub</category><category>GitHub Enterprise Server</category><category>RCE</category><category>Command Injection</category></item><item><title>Checkmarx GitHub Repository Data Leaked Following Supply Chain Attack</title><link>https://runtimerebel.com/blog/checkmarx-github-repository-data-leaked-following-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/checkmarx-github-repository-data-leaked-following-supply-chain-attack</guid><description>Checkmarx confirms internal GitHub repository data was published on the dark web following a March 2026 supply chain incident. Learn the impact and TTPs.</description><pubDate>Mon, 27 Apr 2026 16:37:34 GMT</pubDate><category>Checkmarx</category><category>GitHub</category><category>Supply Chain Attack</category><category>Data Leak</category><category>DevSecOps</category></item><item><title>AI-Assisted Supply Chain Attack Targets GitHub Misconfigurations</title><link>https://runtimerebel.com/blog/ai-assisted-supply-chain-attack-targets-github-misconfigurations</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-assisted-supply-chain-attack-targets-github-misconfigurations</guid><description>Analysis of the AI-assisted PRT-scan supply chain attack targeting GitHub misconfigurations. Learn about automated threats and securing repositories.</description><pubDate>Tue, 07 Apr 2026 00:41:26 GMT</pubDate><category>PRT Scan</category><category>GitHub</category><category>AI</category><category>Supply Chain Attack</category><category>Misconfiguration</category></item><item><title>Fake GitHub Repositories Deliver Vidar Infostealer via Claude Leak</title><link>https://runtimerebel.com/blog/fake-github-repositories-deliver-vidar-infostealer-via-claude-leak</link><guid isPermaLink="true">https://runtimerebel.com/blog/fake-github-repositories-deliver-vidar-infostealer-via-claude-leak</guid><description>Threat actors are exploiting the Claude Code leak, deploying fake GitHub repositories to distribute Vidar infostealer malware, targeting unsuspecting developers and…</description><pubDate>Fri, 03 Apr 2026 00:39:40 GMT</pubDate><category>Claude Code</category><category>GitHub</category><category>Vidar Infostealer</category><category>Malware</category><category>Supply Chain Attack</category></item><item><title>OpenAI Codex Vulnerability Exposed GitHub Tokens via OAuth Flaw</title><link>https://runtimerebel.com/blog/openai-codex-vulnerability-exposed-github-tokens-via-oauth-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-codex-vulnerability-exposed-github-tokens-via-oauth-flaw</guid><description>Researchers discovered a critical OpenAI Codex vulnerability allowing GitHub token theft via OAuth flaws, risking unauthorized access to private repositories.</description><pubDate>Tue, 31 Mar 2026 08:32:36 GMT</pubDate><category>OpenAI</category><category>Codex</category><category>GitHub</category><category>OAuth</category><category>Credential Theft</category></item><item><title>OpenAI Patches ChatGPT Data Exfiltration and Codex Token Flaws</title><link>https://runtimerebel.com/blog/openai-patches-chatgpt-data-exfiltration-and-codex-token-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-patches-chatgpt-data-exfiltration-and-codex-token-flaws</guid><description>OpenAI addresses high-impact vulnerabilities in ChatGPT and Codex that enabled unauthorized data exfiltration and exposure of sensitive GitHub tokens.</description><pubDate>Mon, 30 Mar 2026 20:17:42 GMT</pubDate><category>OpenAI</category><category>ChatGPT</category><category>Codex</category><category>Data Exfiltration</category><category>Check Point</category><category>GitHub</category></item><item><title>GitGuardian 2026 Report: Analyzing the 34% Surge in Secrets Sprawl</title><link>https://runtimerebel.com/blog/gitguardian-2026-report-analyzing-the-34-surge-in-secrets-sprawl</link><guid isPermaLink="true">https://runtimerebel.com/blog/gitguardian-2026-report-analyzing-the-34-surge-in-secrets-sprawl</guid><description>GitGuardian&apos;s 2026 report reveals 29 million leaked secrets on GitHub in 2025. Learn how AI and hardcoded credentials impact enterprise security posture.</description><pubDate>Mon, 30 Mar 2026 12:26:38 GMT</pubDate><category>GitGuardian</category><category>Secrets Sprawl</category><category>GitHub</category><category>DevSecOps</category><category>Hard Coded Credentials</category></item><item><title>GitHub Malware Campaign: Fake VS Code Alerts Target Developers</title><link>https://runtimerebel.com/blog/github-malware-campaign-fake-vs-code-alerts-target-developers</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-malware-campaign-fake-vs-code-alerts-target-developers</guid><description>Attackers exploit GitHub Discussions to push malware via fake VS Code security alerts. Learn the TTPs used to target developers and how to mitigate risk.</description><pubDate>Fri, 27 Mar 2026 20:15:23 GMT</pubDate><category>GitHub</category><category>Visual Studio Code</category><category>Phishing</category><category>Malware</category><category>Infostealer</category><category>Developer Security</category></item><item><title>GitHub Copilot Autofix: AI-Driven Vulnerability Remediation in GHAS</title><link>https://runtimerebel.com/blog/github-copilot-autofix-ai-driven-vulnerability-remediation-in-ghas</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-copilot-autofix-ai-driven-vulnerability-remediation-in-ghas</guid><description>GitHub integrates AI-powered scanning into Advanced Security to detect and remediate vulnerabilities across more languages using Copilot Autofix.</description><pubDate>Thu, 26 Mar 2026 00:39:20 GMT</pubDate><category>GitHub</category><category>AI Security</category><category>Copilot Autofix</category><category>Vulnerability Management</category><category>Code Scanning</category></item><item><title>Malicious GitHub OpenClaw Deployer Repos Deliver Trojans</title><link>https://runtimerebel.com/blog/malicious-github-openclaw-deployer-repos-deliver-trojans</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-github-openclaw-deployer-repos-deliver-trojans</guid><description>Analysts uncover an AI-assisted campaign using over 300 poisoned GitHub repositories like OpenClaw Deployer to distribute infostealers to developers.</description><pubDate>Tue, 24 Mar 2026 16:30:07 GMT</pubDate><category>GitHub</category><category>OpenClaw</category><category>Infostealer</category><category>Supply Chain Attack</category><category>Ai Assisted Threats</category></item><item><title>ForceMemo: Credential Theft Compromises Python Repositories</title><link>https://runtimerebel.com/blog/forcememo-credential-theft-compromises-python-repositories</link><guid isPermaLink="true">https://runtimerebel.com/blog/forcememo-credential-theft-compromises-python-repositories</guid><description>Researchers reveal ForceMemo, a campaign exploiting credentials stolen via GlassWorm to compromise hundreds of GitHub accounts and Python repositories.</description><pubDate>Mon, 16 Mar 2026 12:24:53 GMT</pubDate><category>ForceMemo</category><category>GlassWorm</category><category>GitHub</category><category>Python</category><category>Supply Chain Attack</category><category>Credential Theft</category></item><item><title>Over 100 GitHub Repositories Distributing BoryptGrab Stealer</title><link>https://runtimerebel.com/blog/over-100-github-repositories-distributing-boryptgrab-stealer</link><guid isPermaLink="true">https://runtimerebel.com/blog/over-100-github-repositories-distributing-boryptgrab-stealer</guid><description>A large-scale campaign on GitHub utilizes over 100 repositories to distribute BoryptGrab, an info-stealer targeting crypto wallets and browser data.</description><pubDate>Sat, 07 Mar 2026 16:09:43 GMT</pubDate><category>BoryptGrab</category><category>GitHub</category><category>Infostealer</category><category>Python</category><category>Malware Campaign</category></item></channel></rss>