< ciso
brief />
Tag Banner

All news with #github tag

153 articles

Over 543,000 Valid Credentials Exposed on GitHub

🔒 Truffle Security scanned 224 million GitHub repositories and found 543,699 unique credentials that remained valid in July, appearing across more than 1.1 million files and forks. The median exposure time for a credential was 784 days, with about 10% older than 6.3 years and some dating back to 2009. GitHub's Push Protection reduced exposures in covered categories by 53%, but many secrets (like DB strings and Google API keys) remain outside its default scope. Researchers urge immediate rotation, history cleanup, and automated expiration of secrets.
read more →

Leaked GitHub App keys risk organization takeover

🔐 GitGuardian discovered hundreds of publicly exposed GitHub App private keys that remain valid unless manually revoked. Their testing found many keys granted read or write access to private repositories and some allowed organization administration, enabling potential takeovers. The exposed keys included apps used by multiple organizations and internal one-off bots, increasing supply-chain risk. Experts recommend routine key rotation and prompt revocation to limit long-lived exposure.
read more →

Hundreds of GitHub App private keys still valid

🔒 Research from GitGuardian found thousands of exposed GitHub App private keys in public code, with 474 still authenticating as 440 distinct Apps. The leaked keys never expire unless manually revoked, enabling holders to request indistinguishable access tokens and potentially gain wide repository and organizational privileges. Several high-impact keys affected private repositories and organization administration, prompting coordinated disclosures and key rotations.
read more →

Detecting and Quarantining Exposed AWS IAM Keys

🔎 This article examines how AWS mitigates publicly exposed IAM access keys through the AWSCompromisedKeyQuarantine managed policy, tracing its evolution across versions and explaining its role in responding to leaked credentials. It details the GitHub secret scanning partnership with AWS, a real-world timeline from a public exposure test, and practical monitoring strategies security teams can use to detect quarantine events in their logging environments. The piece also outlines Palo Alto Networks services that can assist organizations in assessment and incident response.
read more →

Attacker Hijacks AI Coding Assistant, Spreads Worm

🛡️ Mandiant reports an attacker hijacked an active AI coding-assistant session at an unnamed SaaS provider and used it to install an infostealer via a poisoned PyPI package. The attacker stole GitHub OAuth tokens and deployed the self-spreading Shai-Hulud worm across about 100 internal repositories, exfiltrating secrets and source code. Mandiant recommends verifying AI-recommended dependencies with checksums and allowlists, restricting extension access to secrets, and routing dependencies through controlled internal repositories to protect AI-assisted development.
read more →

GitHub outage confirmed — widespread service errors

⚠️ GitHub confirmed a widespread outage on August 17, 2026, reporting elevated error rates across the website, API, Actions, Pull Requests, and related services. The company observed ~20% error rates for web and API traffic, and roughly 50% errors for archive and raw repository downloads. Authentication services such as SAML and OIDC, plus SCIM and Team Sync, are affected, and GitHub Actions and Copilot reported degraded availability. The incident is under investigation and the root cause has not been disclosed.
read more →

Mozilla rotates GPG signing key after accidental exposure

🔐 Mozilla updated the GPG subkey used to sign Firefox and Thunderbird artifacts after an unencrypted copy of the previous subkey was inadvertently committed to a private GitHub repository. The organization says the exposure risk is low because repository access was limited and its audit found no evidence of unauthorized access. Mozilla revoked the old key, published the new public key and revocation, and provided instructions for users who manually verify signatures or use RPM-based Linux distributions.
read more →

Using GitHub telemetry as an EDR-style detector

🔍 Researchers at Black Hat USA 2026 demonstrated that GitHub’s native telemetry can be used like an EDR to detect supply-chain attacks by monitoring event streams, webhooks, API data, and Git history. Their open-source GitHub Threat Detector implements behavioral detections from recurring attacker techniques—such as forged commit metadata, mass tag poisoning, workflow abuse, and OIDC token misuse—into correlated rules. The tool uses a PostgreSQL-backed activity store for historical correlation and includes production and beta detection rules, though it faces practical limits from disabled webhooks and API rate limits.
read more →

Malicious Solidity Pro VS Code Extensions Steal Wallets

🔒 Researchers have identified malicious Visual Studio Code extensions named Solidity Pro that evolved from fetching encrypted payloads to a full-featured information stealer. The extensions, distributed under names like helper-beeps.solidity-pro and web3devtoolsx.solidity-pro, harvest browser profiles, crypto wallets, SSH keys, API tokens, and more, then exfiltrate data via a Telegram bot. The malware uses heavy obfuscation, staged clean releases, and randomized delayed activation to evade detection and marketplace review.
read more →

Automated Issue Triage Reduces Open Issues Fast

🛠️ Cloudflare ran an automated triage pipeline on the Astro repository, using isolated AI subagents to read, reproduce, diagnose, and ship preview fixes for incoming bug reports. The pipeline—implemented as a GitHub Action and generalized into the Flue framework—reduced open issues from over 200 to about 30 and aims for zero. The system emphasizes transparency, sequential reasoning, and maintainability, and the triage logic was extracted into a standalone repo, triagebot-action, for reuse and adaptation.
read more →

AWS Transform Continuous Modernization Now Generally Available

🔍 AWS Transform continuous modernization is now generally available in all Regions that support AWS Transform. It enables engineering teams to analyze and remediate technical debt across GitHub, GitLab, and Bitbucket repositories at scale, with on-demand or scheduled analyses and prioritization across technical debt, security, agentic readiness, modernization readiness, and custom criteria. Users can create remediations that open pull requests or merge requests, run analyses in their AWS account, and maintain control of source code. Additional workflows are supported via the AWS Transform Kiro Power, agent plugins, and CLI for IDE and terminal use, local analysis, and remote execution on Amazon EC2 or AWS Batch.
read more →

GitHub adds three-day Dependabot cooldown default

🔒 GitHub introduced a three-day cooldown in Dependabot that delays version-update pull requests for at least 72 hours after a release by default, while security updates continue to be issued immediately. The cooldown is configurable via dependabot.yml, letting teams set a different interval to suit their workflows. GitHub framed the change as a mitigation against short-lived poisoned package releases that spread quickly before removal, and recommended it be used alongside other defenses such as lockfiles and scoped tokens.
read more →

GitHub and PyPI add time-based supply chain controls

🛡️ GitHub and PyPI have implemented time-based defenses to reduce supply chain attack risk. GitHub’s Dependabot now defaults to a 72-hour cooldown before applying package updates, while PyPI blocks adding new files to releases older than 14 days. These measures aim to limit the impact of token or workflow compromises and complement other best practices such as lockfiles and restricted tokens.
read more →

GitHub halves public bug bounty payouts starting July 27

🔔 GitHub will cut public bug bounty payments by roughly half at every severity level beginning July 27, 2026, moving from flexible ranges to fixed payouts. Critical rewards drop to $10,000 while the invite-only VIP tier will pay $30,000 or more. Reports submitted before the cutoff keep prior terms. GitHub says the change aims to reduce noise and speed responses for established researchers while retaining discretionary bonuses for exceptional work.
read more →

Massive FakeGit campaign leverages GitHub to spread malware

🔎 Researchers uncovered the FakeGit campaign using some 7,600 malicious GitHub repositories to distribute SmartLoader and StealC malware, amassing over 14 million download events. Many repos impersonated legitimate tools and AI skills, employing an AgentBaiting technique to attract AI agents and developers. The campaign reused tactics from a prior Lumma Stealer operation, and Island recommends isolating and vetting AI skills, rotating secrets, and validating publishers.
read more →

The SaaS blind spot: visibility gaps in cloud apps

🔍 Most organizations invest heavily in cloud security yet cannot reliably answer who has admin or privileged access inside their SaaS tenants. The author highlights how misconfigurations, forgotten OAuth integrations, and default sharing settings in platforms like Salesforce, GitHub, and Microsoft lead to widespread, quiet data exposures. Practical steps — audit connected apps, tighten guest sharing, disable legacy auth, and run quarterly access reviews — can reduce risk while SaaS security posture management (SSPM) tools provide the deeper visibility needed.
read more →

CISA Details Response to Exposed AWS GovCloud Keys

🔒 The US Cybersecurity and Infrastructure Security Agency (CISA) detailed its response after a contractor’s personal GitHub repository exposed AWS GovCloud credentials and internal build code. CISA’s OCIO began incident response on May 15, quickly mitigating exposure and confirming no customer data was leaked or credentials used outside CISA environments. The agency emphasized lessons learned, including stronger repo controls, improved logging, adoption of zero trust principles, and clearer reporting channels for researchers.
read more →

Dormant GitHub Accounts Exploited to Scrape Orgs

🔎 Datadog Security Labs warns of coordinated campaigns using dormant or compromised GitHub accounts and exposed personal access tokens to enumerate organizations via the GitHub API. Operators use automated scraping tools, aged "ghost" accounts, and legitimate-sounding user agents to blend into normal API traffic, primarily collecting public data but occasionally cloning private repositories. The activity leverages unauthenticated API surfaces and GraphQL queries to map repos, memberships, followers, and other artifacts for reconnaissance.
read more →

npm 12 defaults disable risky install scripts

🔒 GitHub released npm v12 which disables install scripts by default and deprecates 2FA-bypass granular access tokens. The update makes lifecycle scripts, Git dependencies, and remote URL deps opt-in, requiring an explicit approval workflow and an allowlist committed to package.json. It also restricts GAT capabilities for account and publishing actions, with staged publishing and OIDC recommended for automation.
read more →

GitHub API abuse fuels enterprise reconnaissance

🔎 Datadog Security Research has tracked sustained abuse of GitHub’s public APIs where automated scanners, leaked credentials, and ghost accounts map organizations and members. Attackers harvest source code, secrets, and pipeline data by blending requests into normal traffic and leveraging the /graphql endpoint and REST org-mapping calls. Detection requires auditing user agents, token types, and unusual actor behavior, while enterprises should enable audit log streaming, MFA, access reviews, and credential scanning.
read more →