Security News

Ubuntu-Maker Canonical’s GitHub Account Gets Hacked
2019-07-07 16:03

An unknown hacker yesterday successfully managed to hack into the official GitHub account of Canonical, the company behind the Ubuntu Linux project and created 11 new empty repositories. It...

Week in review: BlueKeep, GitHub automated security fixes, reducing the threat of legacy apps
2019-06-02 18:00

Here’s an overview of some of last week’s most interesting news, articles and podcasts: Attackers are exploiting WordPress plugin flaw to inject malicious scripts Attackers are leveraging an...

Git your patches here! GitHub offers to brew automatic pull requests loaded with vuln fixes
2019-05-30 07:12

Your repo's dependencies need updating to close a hole? We're way ahead of you, pal GitHub can now automagically offer security patches for projects' third-party dependencies.…

GitHub introduces Dependabot-powered automated security fixes
2019-05-28 10:05

GitHub, the largest code-hosting site in the world, has announced many new features and changes at the 2019 GitHub Satellite conference that took place last week in Berlin. The feature that drew...

GitHub Adds New Tools to Help Developers Secure Code
2019-05-24 17:12

Microsoft-owned GitHub on Thursday announced the introduction of several new security tools and features designed to help developers secure their code. read more

Chinese dev jailed and fined for posting DJI's private keys on Github
2019-04-30 07:10

Hapless soul repents 'unintentionally' sharing drone makers privates in repo A Chinese software developer who previously expressed suicidal thoughts has been jailed after putting one of drone...

Cybercriminals Using GitHub to Host Phishing Kits
2019-04-25 17:02

Free code repositories on the Microsoft-owned GitHub have been abused since at least mid-2017 to host phishing websites, according to researchers from Proofpoint. read more

Thousands of API and cryptographic keys leaking on GitHub every day
2019-03-25 11:04

Researchers have found that one of the most popular source code repositories in the world is still housing thousands of publicly accessible user credentials.

Slack, GitHub Abused by New SLUB Backdoor in Targeted Attacks
2019-03-08 14:22

Researchers from Trend Micro have come across a new piece of malware that abuses GitHub and Slack for command and control (C&C) communications. read more

Guess who's addicted to GitHub, busy on Slack, stuck in 2015? No, not another hipster: It's the Slub backdoor malware
2019-03-08 07:04

Panic, flee, cry – or just update Windows for fsck's sake A new malware strain tapped into GitHub posts and Slack channels to siphon precious data from infected Windows PCs, it is claimed.…