Skip to content

company · 24 records

GitHub

  • Photo: The Hacker News
    Tech & Cyber

    Attackers exploit critical Fastjson vulnerability despite lack of security patches

    Security firms report active exploitation of a critical Fastjson RCE vulnerability with no patched version currently available.

    2 outlets Cyber read
  • Photo: The Hacker News
    Tech & Cyber

    Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus

    Attackers are distributing a fake LastPass Authenticator installer on GitHub that uses a malicious, Microsoft-signed kernel driver to disable security software and deploy a password stealer.

    1 outlet
  • Photo: The Hacker News
    Tech & Cyber

    Jade Sleet Linked to Indian IT Provider Breach With macOS Backdoors

    The North Korean hacking group Jade Sleet compromised an Indian IT services company using macOS backdoors.

    1 outlet Markets read
  • Photo: Aaj Tak
    Tech & Cyber

    Researchers exploit ChatGPT using Anthropic tool to expose security vulnerabilities

    Cybersecurity researchers discovered a vulnerability in ChatGPT by using an Anthropic tool to exploit a security flaw.

    2 outlets Markets read
  • Photo: The Hacker News
    Tech & Cyber

    Researchers Use Claude Opus 5 to Chain Flaws Into OpenAI Access

    Researchers exploited chained flaws in Discourse and OpenAI's login system to gain unauthorized access to internal staff accounts.

    1 outlet Markets read Cyber read
  • Photo: The Hacker News
    Tech & Cyber

    CrowdSec Says TanStack npm Attack Led to Copy of GitHub Repositories

    CrowdSec reported that an attacker used a former employee's compromised GitHub account to steal 170 private repositories and investor information.

    1 outlet Markets read Cyber read
  • Photo: The Hacker News
    Tech & Cyber

    Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories

    The threat group Transparent Tribe is using new Rust-based malware and private GitHub repositories for C2 in attacks against government and defense targets.

    1 outlet
  • Photo: The Hacker News
    Tech & Cyber

    Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

    A vulnerability in four AI coding agents allows malicious plugin code to be swapped despite version pinning.

    1 outlet
  • Photo: The Hacker News
    Tech & Cyber

    Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven Stealer

    A threat actor created the PhantomRaven information stealer using LLMs to facilitate fraudulent bug bounty submissions.

    1 outlet Markets read
  • Photo: The Hacker News
    Tech & Cyber

    Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

    An attacker hijacked an AI coding-assistant session to deploy the Shai-Hulud worm across approximately 100 internal software repositories.

    1 outlet
  • Photo: The Hacker News
    Tech & Cyber

    Shai-Hulud's Reach Just Grew to 469 Credential Locations

    The Shai-Hulud infostealer worm has expanded its credential scanning capabilities across 469 locations in developer and CI/CD environments.

    1 outlet
  • Photo: The Hacker News
    Tech & Cyber

    Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

    Threat actors are increasingly favoring repeatable, standardized attack playbooks over novel techniques to maximize operational efficiency and volume.

    1 outlet Markets read
  • Photo: The Hacker News
    Tech & Cyber

    Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

    A new Android trojan called StreamRat is being distributed via malicious ads on Meta and TikTok platforms.

    1 outlet
  • Photo: The Hacker News
    Tech & Cyber

    Phishing campaign targets 46 countries with United States as primary focus

    A phishing campaign using fake documents to trick victims into installing legitimate remote monitoring and management software has targeted 46 countries with the United States as its primary focus.

    1 outlet
  • Photo: The Hacker News
    Tech & Cyber

    Attackers target cPanel and WHM servers using compromised GitHub Actions repositories

    Researchers report a large-scale campaign weaponizing compromised GitHub Actions repositories to target vulnerable cPanel and WebHost Manager servers for credential theft.

    1 outlet Cyber read
  • Photo: The Hacker News
    Tech & Cyber

    Researchers identify three passkey hijacking vulnerabilities in Google Chrome Password Manager

    Unit 42 researchers disclosed three passkey hijacking vulnerabilities in Google Chrome Password Manager requiring local malware compromise on Windows systems.

    1 outlet
  • Photo: The Hacker News
    Tech & Cyber

    Security researchers identify spear phishing attack targeting law firm

    Security researchers at Blackpoint Cyber disclosed details of a spear-phishing campaign deploying the HollowFrame loader and Matryoshka backdoor against an unspecified law firm.

    1 outlet
  • Photo: The Hacker News
    Tech & Cyber

    Critical vulnerability discovered in Ruflo AI orchestration platform

    Security researchers have identified a critical vulnerability in the open-source Ruflo AI orchestration platform that allows unauthenticated attackers to execute commands and poison AI memory.

    1 outlet Cyber read
  • Photo: The Times of India
    Business & Markets

    Microsoft executives question Satya Nadella over AI compute resource allocation strategy

    Microsoft executives question CEO Satya Nadella's AI compute allocation strategy following GitHub outages and a 24 percent stock drop ahead of Q4 earnings.

    1 outlet Markets read
  • Photo: The Hacker News
    Tech & Cyber

    GitHub and PyPI introduce time-based defenses against supply chain attacks

    GitHub and PyPI have implemented time-based security measures in their dependency tools to mitigate supply-chain attacks.

    2 outlets
  • Photo: BleepingComputer
    Tech & Cyber

    Researchers identify campaign using GitHub repositories to target cPanel servers

    Researchers report a large-scale campaign weaponizing compromised GitHub Actions repositories to target vulnerable cPanel and WebHost Manager servers for credential theft.

    2 outlets Cyber read
  • Photo: The Hacker News
    Tech & Cyber

    New exploit allows users to impersonate domain controllers in Active Directory

    Researchers published an exploit for a vulnerability in Microsoft's Active Directory Certificate Services that enables low-privileged users to impersonate Domain Controllers.

    1 outlet Cyber read
  • Photo: The Hacker News
    Tech & Cyber

    GitHub reduces public bug bounty payouts and introduces new VIP reward tier

    GitHub cuts public bug bounty payouts by half starting July 27, 2026, while increasing rewards for a VIP tier and citing AI-generated report noise as a driver for the policy change.

    1 outlet
  • Photo: The Hacker News
    Tech & Cyber

    Microsoft Azure DevOps flaw allows unauthorized access to sensitive source code

    A vulnerability in Microsoft's official Azure DevOps MCP server allows hidden HTML comments in pull request descriptions to hijack AI coding agents, enabling unauthorized access to source code, secrets, and work items across projects via a confused-deputy attack.

    1 outlet Markets read
  • GitHub — every record | Prism