⤷ Title: GitBait Phishing Campaign Targets 12 Mexican Banks via GitHub Pages
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 23 Jun 2026 09:22:00 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Credential Harvesting #Financial Sector #GitBait #GitHub Pages #Mexican banks #phishing #SheetBest #Telegram bot
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 23 Jun 2026 09:22:00 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Credential Harvesting #Financial Sector #GitBait #GitHub Pages #Mexican banks #phishing #SheetBest #Telegram bot
Daily CyberSecurity
GitBait Phishing Campaign Targets 12 Mexican Banks via GitHub Pages
The GitBait phishing campaign abuses GitHub Pages and the SheetBest API to steal banking credentials from at least 12 Mexican financial institutions.
⤷ Title: ‘Cordyceps’ CI/CD Flaw Exposes Microsoft, Google, Apache Repos to Pipeline Hijacking
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Tue, 23 Jun 2026 16:31:16 +0000
════════════════════════
⌗ Tags: #Security #CI/CD #Cordyceps #Cybersecurity #GitHub #Novee #Supply Chain #Vulnerability
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Tue, 23 Jun 2026 16:31:16 +0000
════════════════════════
⌗ Tags: #Security #CI/CD #Cordyceps #Cybersecurity #GitHub #Novee #Supply Chain #Vulnerability
Hackread
‘Cordyceps’ CI/CD Flaw Exposes Microsoft, Google, Apache Repos to Pipeline Hijacking
Novee Security reveals Cordyceps, a CI/CD vulnerability in GitHub Actions workflows that let anonymous users poison builds and expose tokens across major projects today.
⤷ Title: 8 GitHub Repositories That Make Google Dorking Ridiculously Powerful
════════════════════════
𐀪 Author: Devansh Patel
════════════════════════
ⴵ Time: Sun, 28 Jun 2026 14:07:34 GMT
════════════════════════
⌗ Tags: #google #github #ethical_hacking #cybersecurity #cyber_security_awareness
════════════════════════
𐀪 Author: Devansh Patel
════════════════════════
ⴵ Time: Sun, 28 Jun 2026 14:07:34 GMT
════════════════════════
⌗ Tags: #google #github #ethical_hacking #cybersecurity #cyber_security_awareness
Medium
8 GitHub Repositories That Make Google Dorking Ridiculously Powerful
Most people think Google is just a search engine.
⤷ Title: Gemini CLI Vulnerability Hits Maximum CVSS 10 Score
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 01:16:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_12537 #Gemini CLI #GitHub Actions #Vulnerability
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 29 Jun 2026 01:16:58 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_12537 #Gemini CLI #GitHub Actions #Vulnerability
Daily CyberSecurity
Gemini CLI Vulnerability Hits Maximum CVSS 10 Score
A critical Gemini CLI vulnerability (CVE-2026-12537) exposes developer workflows to maximum severity attacks. Google disclosed this CVSS 10 rating flaw recently. TL;DR A critical Gemini CLI vulner…
⤷ Title: Android Signing Key Leak Exposes 278 Apps to Fake Updates
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 16:10:10 +0000
════════════════════════
⌗ Tags: #Data Leak #Android Signing Key #APK Re_signing #Baidu CarLife #Baidu Keyboard #GitHub Secrets Exposure #Keystore Leak #supply chain attack
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 16:10:10 +0000
════════════════════════
⌗ Tags: #Data Leak #Android Signing Key #APK Re_signing #Baidu CarLife #Baidu Keyboard #GitHub Secrets Exposure #Keystore Leak #supply chain attack
Information Security News
Android Signing Key Leak Exposes 278 Apps to Fake Updates
A digital signature should prove that an Android app truly comes from its original developer. New research shows how a single leaked signing key can turn that trust mechanism into a supply-chain w…
⤷ Title: GitHub CD-ROM Repository: Physical Code Discs
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 13:53:59 +0000
════════════════════════
⌗ Tags: #Technology #CD_ROM #github #physical media #Sony PlayStation
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 03 Jul 2026 13:53:59 +0000
════════════════════════
⌗ Tags: #Technology #CD_ROM #github #physical media #Sony PlayStation
Daily CyberSecurity
GitHub CD-ROM Repository: Physical Code Discs
Sony recently announced that it will cease production of physical game discs for new releases starting in January 2028. This pivotal decision signals a complete transition for the Sony PlayStation…
⤷ Title: GitLost: GitHub’s AI Agent Tricked Into Leaking Private Repository Data
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 13:00:20 +0000
════════════════════════
⌗ Tags: #Security #Agentic AI #Cybersecurity #GitHub #GitHub Actions #GitLost #Privacy #Repository #Vulnerability
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Tue, 07 Jul 2026 13:00:20 +0000
════════════════════════
⌗ Tags: #Security #Agentic AI #Cybersecurity #GitHub #GitHub Actions #GitLost #Privacy #Repository #Vulnerability
Hackread
GitLost: GitHub’s AI Agent Tricked Into Leaking Private Repository Data
Noma Labs details GitLost, a prompt injection flaw that made GitHub's AI agent expose private repo data through a crafted public issue and guardrail failures.
⤷ Title: GitHub Agentic Workflows Vulnerability Exposed
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 13:00:08 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI security #Github #GitLost #Prompt Injection
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 09 Jul 2026 13:00:08 +0000
════════════════════════
⌗ Tags: #Vulnerability #AI security #Github #GitLost #Prompt Injection
Information Security News
GitHub Agentic Workflows Vulnerability Exposed
A seemingly mundane submission within a bug-tracking system can masquerade as a covert directive for artificial intelligence. Recently, researchers at Noma Labs demonstrated how a singular GitHub …
⤷ Title: Install Burp Suite Professional 2026 (Linux )| By Dharavath Nagaraju
════════════════════════
𐀪 Author: Dharavathnagaraju
════════════════════════
ⴵ Time: Fri, 10 Jul 2026 19:06:09 GMT
════════════════════════
⌗ Tags: #burpsuite_profissional #ethical_hacking #linux #github #web_security
════════════════════════
𐀪 Author: Dharavathnagaraju
════════════════════════
ⴵ Time: Fri, 10 Jul 2026 19:06:09 GMT
════════════════════════
⌗ Tags: #burpsuite_profissional #ethical_hacking #linux #github #web_security
Medium
Install Burp Suite Professional 2026 (Linux )| By Dharavath Nagaraju
Burp Suite Professional is one of the most widely used tools for web application security testing, providing features that help security…
⤷ Title: Malicious Go Module Exposes a 222-Repository GitHub Lure Network
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 07:11:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AsyncRAT #GitHub lure network #malicious Go module #Operation Muck and Load #Socket #Software Supply Chain #Vidar Infostealer
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 07:11:10 +0000
════════════════════════
⌗ Tags: #Cybercriminals #AsyncRAT #GitHub lure network #malicious Go module #Operation Muck and Load #Socket #Software Supply Chain #Vidar Infostealer
Daily CyberSecurity
Malicious Go Module Exposes a 222-Repository GitHub Lure Network
Actor / group Unnamed actor tracked as “Operation Muck and Load”; overlaps with the ischhfd83 cluster Activity type Software supply-chain lures and Windows malware staging Targets / vi…
⤷ Title: South Korean Police Uncover Massive GitHub Token Leak
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 12:41:19 +0000
════════════════════════
⌗ Tags: #Data Leak #cybersecurity #data breach #Github #Investigation
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 12:41:19 +0000
════════════════════════
⌗ Tags: #Data Leak #cybersecurity #data breach #Github #Investigation
Information Security News
South Korean Police Uncover Massive GitHub Token Leak
The Initial Discovery Investigators found a single key on a hacker. This discovery led South Korean police to a massive GitHub token leak. Law enforcement soon discovered over 500 compromised user…
⤷ Title: Grok Build Goes Open Source for Community Audits but GitHub Issues and PRs Stay Closed
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 15:08:11 +0000
════════════════════════
⌗ Tags: #Technology #Data Privacy #github #Grok Build #open_source #SpaceXAI
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 16 Jul 2026 15:08:11 +0000
════════════════════════
⌗ Tags: #Technology #Data Privacy #github #Grok Build #open_source #SpaceXAI
Daily CyberSecurity
Grok Build Goes Open Source for Community Audits but GitHub Issues and PRs Stay Closed
Not long ago, the AI coding tool Grok Build triggered fierce community backlash for uploading developers’ complete repositories. Remarkably, SpaceXAI still has not admitted to collecting rep…
⤷ Title: 292 Fake GitHub Repositories Deliver BoryptGrab Infostealer to Windows Users
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 08:21:34 +0000
════════════════════════
⌗ Tags: #Malware #Arctic Wolf #BoryptGrab #brand impersonation #DLL side_loading #github #Infostealer
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Fri, 17 Jul 2026 08:21:34 +0000
════════════════════════
⌗ Tags: #Malware #Arctic Wolf #BoryptGrab #brand impersonation #DLL side_loading #github #Infostealer
Daily CyberSecurity
292 Fake GitHub Repositories Deliver BoryptGrab Infostealer to Windows Users
At a Glance Malware family BoryptGrab-lineage in-memory infostealer Threat actor Unattributed; financially motivated, likely Russian-speaking Targets Opportunistic Windows users across sectors Del…
⤷ Title: GitHub Actions Abuse Powers a Distributed cPanel and WHM Attack Campaign
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 02:29:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cPanel and WHM exploitation #Credential Theft #CVE_2026_41940 #GitHub Actions abuse #Packagist #supply chain attack
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 02:29:19 +0000
════════════════════════
⌗ Tags: #Cybercriminals #cPanel and WHM exploitation #Credential Theft #CVE_2026_41940 #GitHub Actions abuse #Packagist #supply chain attack
Daily CyberSecurity
GitHub Actions Abuse Powers a Distributed cPanel and WHM Attack Campaign
At a Glance Actor or group Unattributed threat actor; no group name published Activity type GitHub Actions abuse, internet scanning, credential theft Targets Internet-facing cPanel and WHM servers…
⤷ Title: GitHub Overhauls Bug Bounty Program with New VIP Tier
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 08:08:43 +0000
════════════════════════
⌗ Tags: #Technology #artificial intelligence #bug bounty #cybersecurity #github #HackerOne
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 08:08:43 +0000
════════════════════════
⌗ Tags: #Technology #artificial intelligence #bug bounty #cybersecurity #github #HackerOne
Daily CyberSecurity
GitHub Overhauls Bug Bounty Program with New VIP Tier
The Microsoft-owned code repository, GitHub, recently published a blog post announcing a sweeping overhaul of its security initiatives. This transformation primarily abandons the previous floating…
⤷ Title: AgentBaiting Malware Campaign Targets AI MCP Servers
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 14:24:56 +0000
════════════════════════
⌗ Tags: #Malware #AgentBaiting #AI Malware #GitHub Security #MCP Server #StealC
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 14:24:56 +0000
════════════════════════
⌗ Tags: #Malware #AgentBaiting #AI Malware #GitHub Security #MCP Server #StealC
Information Security News
AgentBaiting Malware Campaign Targets AI MCP Servers
Emergence of AgentBaiting Threat Vector The surging popularity of artificial intelligence tools has transformed skill directories into lucrative initial access points. Attackers target Model Conte…
⤷ Title: Case Study: FakeGit Campaign — 7,600 Fake GitHub Repositories Used to Spread Malware
════════════════════════
𐀪 Author: Chandan
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 16:49:50 GMT
════════════════════════
⌗ Tags: #zero_trust_security #security_alert #cybersecurity #github_pages #ethical_hacking
════════════════════════
𐀪 Author: Chandan
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 16:49:50 GMT
════════════════════════
⌗ Tags: #zero_trust_security #security_alert #cybersecurity #github_pages #ethical_hacking
Medium
🚨 Case Study: FakeGit Campaign — 7,600 Fake GitHub Repositories Used to Spread Malware
GitHub has always been one of the most trusted platforms for developers. But what happens when attackers start abusing that trust?
⤷ Title: GitHub Halves Public Bug Bounty Payouts and Unveils VIP Tier
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 12:47:49 +0000
════════════════════════
⌗ Tags: #Technology #bug bounty #cybersecurity #Github #Infosec #Vulnerability Rewards
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Fri, 24 Jul 2026 12:47:49 +0000
════════════════════════
⌗ Tags: #Technology #bug bounty #cybersecurity #Github #Infosec #Vulnerability Rewards
Information Security News
GitHub Halves Public Bug Bounty Payouts and Unveils VIP Tier
Redefining Value in an Automated Era As automated vulnerability discovery becomes increasingly frictionless, software developers place an unprecedented premium on verified, empirical results. Effe…
⤷ Title: The $100,000 GitHub Bug That Started With a Git Push -
════════════════════════
𐀪 Author: The Zarth Dev
════════════════════════
ⴵ Time: Sun, 26 Jul 2026 04:36:11 GMT
════════════════════════
⌗ Tags: #cybersecurity #github #programming #bug_bounty #system_design_interview
════════════════════════
𐀪 Author: The Zarth Dev
════════════════════════
ⴵ Time: Sun, 26 Jul 2026 04:36:11 GMT
════════════════════════
⌗ Tags: #cybersecurity #github #programming #bug_bounty #system_design_interview
Medium
The $100,000 GitHub Bug That Started With a Git Push -
GitHub recently paid $100,000 bug bounty for discovering a critical vulnerability in GitHub’s internal Git infrastructure. The reason lies…
⤷ Title: India Orders GitHub to Block BitChat Repository Within 3 Hours
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sun, 26 Jul 2026 07:05:00 +0000
════════════════════════
⌗ Tags: #Technology #Bitchat #Decentralized Messaging #github #India Censorship #Jack Dorsey #Mesh Network
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sun, 26 Jul 2026 07:05:00 +0000
════════════════════════
⌗ Tags: #Technology #Bitchat #Decentralized Messaging #github #India Censorship #Jack Dorsey #Mesh Network
Daily CyberSecurity
India Orders GitHub to Block BitChat Repository Within 3 Hours
BitChat is a decentralised mesh messaging tool. It comes from a company founded by Twitter co-founder Jack Dorsey. The app builds a mesh network across nearby devices over Bluetooth, so messages h…