In early March, GitHub patched a critical remote code execution vulnerability (CVE-2026-3854) that could have allowed ...
Wiz discovered a critical remote code execution vulnerability in GitHub that exposed millions of repositories.
CVE-2026-3854 (CVSS 8.7) enabled GitHub RCE via git push, risking cross-tenant access to millions of repositories.
Application security company Checkmarx has confirmed that the LAPSUS$ threat group leaked data stolen from its private GitHub ...
This was not a case of stolen credentials, but rather of vulnerability exploitation.
Malicious npm packages have been identified distributing malware that steals credentials and attempts to spread across ...
The Ruby vulnerability is not easy to exploit, but allows an attacker to read sensitive data, start code, and install ...
Self-propagating npm worm steals tokens via postinstall hooks, impacting six packages and expanding supply chain attacks.