Security News

Backdoored GitHub accounts spewed secret sneakerbot software
2019-03-07 15:53

Researchers have uncovered a network of GitHub accounts containing backdoored versions of legitimate software.

GitHub Increases Rewards, Scope For Bug-Bounty Program
2019-02-20 18:34

GitHub is offering unlimited rewards for critical vulnerabilities - and has added "safe harbor" terms to its bug bounty program.

GitHub Increases Bug Bounty Program Rewards, Expands Scope
2019-02-19 18:52

After paying out $250,000 in bug bounties in 2018, GitHub has decided to increase rewards and expand the scope of its bug bounty program. read more

GitHub Helps Developers Keep Dependencies Secure via Dependabot
2019-01-31 19:11

Microsoft-owned GitHub informed developers on Thursday that they can easily ensure that the dependencies used by their applications are always secure and up to date through an integration of its...

New DDoS campaign serving four times the number of packets as 2018's major GitHub attack
2019-01-30 14:33

The potency of DDoS attacks lies in the number of packets being sent rather than the relative bandwidth involved in the attack.

WhiteSource Bolt for GitHub: Free Open Source Vulnerability Management App for Developers
2018-12-05 11:48

Developers around the world depend on open source components to build their software products. According to industry estimates, open source components account for 60-80% of the code base in modern...

We don' need no stinkin' bounties: VirtualBox guest-to-host escape zero-day lands at GitHub
2018-11-07 11:50

Bug hunter rages at wearisome disclosure process An infosec researcher has expressed his frustration with disclosure processes by going public with a zero-day in VirtualBox, Oracle's open-source...

Code of App Security Tool Posted to GitHub
2018-08-20 13:19

Code of DexGuard, software designed to secure Android applications and software development kits (SDKs), was removed from GitHub last week, after being illegally posted on the platform. read more

Leaked GitHub API Token Exposed Homebrew Software Repositories
2018-08-09 13:50

A GitHub API token leaked from Homebrew’s Jenkins provided a security researcher with access to core Homebrew software repositories (repos). read more

Snapchat source code leaked on GitHub – but no one knows why
2018-08-08 15:38

What just befell a "small" piece of SnapChat’s source code, and should users be concerned?