Security News

Chinese dev jailed and fined for posting DJI's private keys on Github
2019-04-30 07:10

Hapless soul repents 'unintentionally' sharing drone makers privates in repo A Chinese software developer who previously expressed suicidal thoughts has been jailed after putting one of drone...

Cybercriminals Using GitHub to Host Phishing Kits
2019-04-25 17:02

Free code repositories on the Microsoft-owned GitHub have been abused since at least mid-2017 to host phishing websites, according to researchers from Proofpoint. read more

Thousands of API and cryptographic keys leaking on GitHub every day
2019-03-25 11:04

Researchers have found that one of the most popular source code repositories in the world is still housing thousands of publicly accessible user credentials.

Slack, GitHub Abused by New SLUB Backdoor in Targeted Attacks
2019-03-08 14:22

Researchers from Trend Micro have come across a new piece of malware that abuses GitHub and Slack for command and control (C&C) communications. read more

Guess who's addicted to GitHub, busy on Slack, stuck in 2015? No, not another hipster: It's the Slub backdoor malware
2019-03-08 07:04

Panic, flee, cry – or just update Windows for fsck's sake A new malware strain tapped into GitHub posts and Slack channels to siphon precious data from infected Windows PCs, it is claimed.…

Backdoored GitHub accounts spewed secret sneakerbot software
2019-03-07 15:53

Researchers have uncovered a network of GitHub accounts containing backdoored versions of legitimate software.

GitHub Increases Rewards, Scope For Bug-Bounty Program
2019-02-20 18:34

GitHub is offering unlimited rewards for critical vulnerabilities - and has added "safe harbor" terms to its bug bounty program.

GitHub Increases Bug Bounty Program Rewards, Expands Scope
2019-02-19 18:52

After paying out $250,000 in bug bounties in 2018, GitHub has decided to increase rewards and expand the scope of its bug bounty program. read more

GitHub Helps Developers Keep Dependencies Secure via Dependabot
2019-01-31 19:11

Microsoft-owned GitHub informed developers on Thursday that they can easily ensure that the dependencies used by their applications are always secure and up to date through an integration of its...

New DDoS campaign serving four times the number of packets as 2018's major GitHub attack
2019-01-30 14:33

The potency of DDoS attacks lies in the number of packets being sent rather than the relative bandwidth involved in the attack.