GitHub supply chain attack sees thousands of tokens and secrets stolen in GhostAction campaign

GhostAction attack stole 3,325 secrets from 327 GitHub accounts GitGuardian helped shut it down and alerted…

Continue Reading

This GitHub trick could let attackers steal secrets from major projects, and no one’s paying attention

Sysdig exposed how a trusted GitHub feature can silently hand control to attackers pull_request_target isn’t just…

Continue Reading

Exposed Git tokens and secrets are being hoovered up by hacker scans

GreyNoise saw a significant increase in scanning activity IPs from Singapore are looking for exposed Git…

Continue Reading