⤷ Title: How I Found 100+ Exposed AWS Keys in Public Git Repos
════════════════════════
𐀪 Author: Anmol Singh Yadav
════════════════════════
ⴵ Time: Mon, 17 Feb 2025 19:46:44 GMT
════════════════════════
⌗ Tags: #cloud_security #aws #devsecops #github_security #hacking
════════════════════════
𐀪 Author: Anmol Singh Yadav
════════════════════════
ⴵ Time: Mon, 17 Feb 2025 19:46:44 GMT
════════════════════════
⌗ Tags: #cloud_security #aws #devsecops #github_security #hacking
Medium
How I Found 100+ Exposed AWS Keys in Public Git Repos
Imagine waking up to find your cloud infrastructure hijacked, your AWS bill skyrocketing overnight, and your sensitive data at risk — all…
⤷ Title: A maintainer’s guide to vulnerability disclosure: GitHub tools to make it simple
════════════════════════
𐀪 Author: Nancy Gariché
════════════════════════
ⴵ Time: Mon, 24 Mar 2025 16:00:33 +0000
════════════════════════
⌗ Tags: #Security #Supply chain security #Vulnerability research #CVE integration #cybersecurity #GitHub Security Tools #open source security #private vulnerability reporting #security advisories #vulnerability disclosure
════════════════════════
𐀪 Author: Nancy Gariché
════════════════════════
ⴵ Time: Mon, 24 Mar 2025 16:00:33 +0000
════════════════════════
⌗ Tags: #Security #Supply chain security #Vulnerability research #CVE integration #cybersecurity #GitHub Security Tools #open source security #private vulnerability reporting #security advisories #vulnerability disclosure
The GitHub Blog
What to do when you receive a vulnerability report: A step-by-step guide for maintainers
A step-by-step guide for open source maintainers on how to handle vulnerability reports confidently from the start.
⤷ Title: Vulnerability Discovery and Exploit Development via GitHub
════════════════════════
𐀪 Author: Esra Kayhan
════════════════════════
ⴵ Time: Sun, 20 Jul 2025 15:23:00 GMT
════════════════════════
⌗ Tags: #exploit_development #github_security #ethical_hacking #cybersecurity #technology
════════════════════════
𐀪 Author: Esra Kayhan
════════════════════════
ⴵ Time: Sun, 20 Jul 2025 15:23:00 GMT
════════════════════════
⌗ Tags: #exploit_development #github_security #ethical_hacking #cybersecurity #technology
Medium
🔍 Vulnerability Discovery and Exploit Development via GitHub
Open-source projects have become indispensable in software development, providing speed and flexibility. However, this accessibility also…
⤷ Title: Securing Your GitHub Codebase: 6 Essential Tools Every Developer Must Know
════════════════════════
𐀪 Author: Vedant Vartak
════════════════════════
ⴵ Time: Fri, 12 Sep 2025 00:53:52 GMT
════════════════════════
⌗ Tags: #code_security #github #github_security #cybersecurity
════════════════════════
𐀪 Author: Vedant Vartak
════════════════════════
ⴵ Time: Fri, 12 Sep 2025 00:53:52 GMT
════════════════════════
⌗ Tags: #code_security #github #github_security #cybersecurity
Medium
Securing Your GitHub Codebase: 6 Essential Tools Every Developer Must Know
Why Repository Security Is Critical in 2025
⤷ Title: How I found Critical Bugs Easily on GitHub
════════════════════════
𐀪 Author: mohamed metwally
════════════════════════
ⴵ Time: Sun, 14 Sep 2025 19:49:07 GMT
════════════════════════
⌗ Tags: #vulnerability_research #cybersecurity #information_disclosure #github_security #bug_bounty
════════════════════════
𐀪 Author: mohamed metwally
════════════════════════
ⴵ Time: Sun, 14 Sep 2025 19:49:07 GMT
════════════════════════
⌗ Tags: #vulnerability_research #cybersecurity #information_disclosure #github_security #bug_bounty
Medium
How I found Critical Bugs Easily on GitHub
Introduction
⤷ Title: Kicking off Cybersecurity Awareness Month 2025: Researcher Spotlights and Enhanced Incentives
════════════════════════
𐀪 Author: Shilpa Kumari
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 15:00:00 +0000
════════════════════════
⌗ Tags: #Security #Vulnerability research #bug bounty #cybersecurity #Cybersecurity Awareness Month #GitHub Security
════════════════════════
𐀪 Author: Shilpa Kumari
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 15:00:00 +0000
════════════════════════
⌗ Tags: #Security #Vulnerability research #bug bounty #cybersecurity #Cybersecurity Awareness Month #GitHub Security
The GitHub Blog
Kicking off Cybersecurity Awareness Month 2025: Researcher spotlights and enhanced incentives
For this year’s Cybersecurity Awareness Month, GitHub’s Bug Bounty team is offering some additional incentives to security researchers!
⤷ Title: Kicking off Cybersecurity Awareness Month 2025: Researcher spotlights and enhanced incentives
════════════════════════
𐀪 Author: Shilpa Kumari
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 15:00:00 +0000
════════════════════════
⌗ Tags: #Security #Vulnerability research #bug bounty #cybersecurity #Cybersecurity Awareness Month #GitHub Security
════════════════════════
𐀪 Author: Shilpa Kumari
════════════════════════
ⴵ Time: Fri, 26 Sep 2025 15:00:00 +0000
════════════════════════
⌗ Tags: #Security #Vulnerability research #bug bounty #cybersecurity #Cybersecurity Awareness Month #GitHub Security
The GitHub Blog
Kicking off Cybersecurity Awareness Month 2025: Researcher spotlights and enhanced incentives
For this year’s Cybersecurity Awareness Month, GitHub’s Bug Bounty team is offering some additional incentives to security researchers!
⤷ Title: How a top bug bounty researcher got their start in security
════════════════════════
𐀪 Author: Shilpa Kumari
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 16:00:00 +0000
════════════════════════
⌗ Tags: #Application security #Security #Supply chain security #Vulnerability research #Web application security #bug bounty #cybersecurity #Cybersecurity Awareness Month #GitHub Security
════════════════════════
𐀪 Author: Shilpa Kumari
════════════════════════
ⴵ Time: Tue, 07 Oct 2025 16:00:00 +0000
════════════════════════
⌗ Tags: #Application security #Security #Supply chain security #Vulnerability research #Web application security #bug bounty #cybersecurity #Cybersecurity Awareness Month #GitHub Security
The GitHub Blog
How a top bug bounty researcher got their start in security
For this year’s Cybersecurity Awareness Month, the GitHub Bug Bounty team is excited to feature another spotlight on a talented security researcher — @xiridium!
⤷ Title: Top security researcher shares their bug bounty process
════════════════════════
𐀪 Author: Shilpa Kumari
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 16:00:00 +0000
════════════════════════
⌗ Tags: #Application security #Security #Supply chain security #Vulnerability research #Web application security #bug bounty #cybersecurity #Cybersecurity Awareness Month #GitHub Security
════════════════════════
𐀪 Author: Shilpa Kumari
════════════════════════
ⴵ Time: Wed, 22 Oct 2025 16:00:00 +0000
════════════════════════
⌗ Tags: #Application security #Security #Supply chain security #Vulnerability research #Web application security #bug bounty #cybersecurity #Cybersecurity Awareness Month #GitHub Security
The GitHub Blog
Top security researcher shares their bug bounty process
For this year’s Cybersecurity Awareness Month, the GitHub Bug Bounty team is excited to put the spotlight on a talented security researcher—@dev-bio!
⤷ Title: Shadow Commits: The Stealthy “Force Push” Attack That Compromised Plone’s GitHub Repositories
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 07:57:22 +0000
════════════════════════
⌗ Tags: #Malware #credential exfiltration #force push attack #GitHub rulesets #GitHub security breach #malicious JavaScript #open source security #Personal Access Token (PAT) #Plone CMS #RCE exploit #Supply Chain Security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Tue, 03 Feb 2026 07:57:22 +0000
════════════════════════
⌗ Tags: #Malware #credential exfiltration #force push attack #GitHub rulesets #GitHub security breach #malicious JavaScript #open source security #Personal Access Token (PAT) #Plone CMS #RCE exploit #Supply Chain Security
Penetration Testing Tools
Shadow Commits: The Stealthy "Force Push" Attack That Compromised Plone’s GitHub Repositories
A stealthy security breach has compromised one of the most prominent open-source content management projects. An anonymous adversary
⤷ Title: What to do when you receive a vulnerability report: A step-by-step guide for maintainers
════════════════════════
𐀪 Author: Nancy Gariché
════════════════════════
ⴵ Time: Mon, 24 Mar 2025 16:00:33 +0000
════════════════════════
⌗ Tags: #Security #Supply chain security #Vulnerability research #CVE integration #cybersecurity #GitHub Security Lab #GitHub Security Tools #open source security #private vulnerability reporting #security advisories #vulnerability disclosure
════════════════════════
𐀪 Author: Nancy Gariché
════════════════════════
ⴵ Time: Mon, 24 Mar 2025 16:00:33 +0000
════════════════════════
⌗ Tags: #Security #Supply chain security #Vulnerability research #CVE integration #cybersecurity #GitHub Security Lab #GitHub Security Tools #open source security #private vulnerability reporting #security advisories #vulnerability disclosure
The GitHub Blog
What to do when you receive a vulnerability report: A step-by-step guide for maintainers
A step-by-step guide for open source maintainers on how to handle vulnerability reports confidently from the start.
⤷ Title: What does a cybersecurity researcher do and how do you get started?
════════════════════════
𐀪 Author: Nancy Gariché
════════════════════════
ⴵ Time: Wed, 29 Jan 2025 17:00:31 +0000
════════════════════════
⌗ Tags: #Security #Vulnerability research #application security #Career in Cybersecurity #cybersecurity #GitHub Security Lab #security research #Vulnerability Detection
════════════════════════
𐀪 Author: Nancy Gariché
════════════════════════
ⴵ Time: Wed, 29 Jan 2025 17:00:31 +0000
════════════════════════
⌗ Tags: #Security #Vulnerability research #application security #Career in Cybersecurity #cybersecurity #GitHub Security Lab #security research #Vulnerability Detection
The GitHub Blog
What does a cybersecurity researcher do and how do you get started?
Discover the exciting world of cybersecurity research: what researchers do, essential skills, and actionable steps to begin your journey toward protecting the digital world.
⤷ Title: Hack the AI agent: Build agentic AI security skills with the GitHub Secure Code Game
════════════════════════
𐀪 Author: Joseph Katsioloudes
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 18:17:59 +0000
════════════════════════
⌗ Tags: #AI & ML #Security #agentic AI security #AI security #coding training #cybersecurity #GitHub Security Lab #secure coding
════════════════════════
𐀪 Author: Joseph Katsioloudes
════════════════════════
ⴵ Time: Tue, 14 Apr 2026 18:17:59 +0000
════════════════════════
⌗ Tags: #AI & ML #Security #agentic AI security #AI security #coding training #cybersecurity #GitHub Security Lab #secure coding
The GitHub Blog
Hack the AI agent: Build agentic AI security skills with the GitHub Secure Code Game
Learn to find and exploit real-world agentic AI vulnerabilities through five progressive challenges in this free, open source game that over 10,000 developers have already used to sharpen their security skills.
⤷ Title: Void Dokkaebi Unmasked: The “Worm-Like” Supply Chain Threat Targeting Developers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:24:51 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain Staging #CI/CD security #Famous Chollima #GitHub Security #infosec #North Korea APT #Open Source Security #supply chain attack #TrendMicro #Void Dokkaebi #VS Code Malware
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 06:24:51 +0000
════════════════════════
⌗ Tags: #Malware #Blockchain Staging #CI/CD security #Famous Chollima #GitHub Security #infosec #North Korea APT #Open Source Security #supply chain attack #TrendMicro #Void Dokkaebi #VS Code Malware
Daily CyberSecurity
Void Dokkaebi Unmasked: The "Worm-Like" Supply Chain Threat Targeting Developers
Void Dokkaebi turns developers into vectors. With 750+ infected repos and malicious VS Code tasks, this supply chain worm is hunting your CI/CD and crypto.
⤷ Title: Checkmarx Falls Victim to Credential Harvesting Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 01:54:29 +0000
════════════════════════
⌗ Tags: #Cybercriminals #breach #Checkmarx #cybersecurity #data exfiltration #GitHub Security #infosec #LAPSUS$ #Malicious code #Software Integrity #supply chain attack #Trivy
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 29 Apr 2026 01:54:29 +0000
════════════════════════
⌗ Tags: #Cybercriminals #breach #Checkmarx #cybersecurity #data exfiltration #GitHub Security #infosec #LAPSUS$ #Malicious code #Software Integrity #supply chain attack #Trivy
Daily CyberSecurity
Checkmarx Falls Victim to Credential Harvesting Attack
Checkmarx discloses a major GitHub breach via a Trivy supply chain flaw. Attackers injected malicious code and exfiltrated data for a month. Get the facts.
⤷ Title: Quasar Linux (QLNX) Emerges to Subvert the Global Software Supply Chain
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 07:50:51 +0000
════════════════════════
⌗ Tags: #Malware #AWS #Credential Harvester #DevSecOps #eBPF #GitHub Security #Kubernetes #Linux malware #malware analysis #QLNX #Quasar Linux #rootkit #supply chain attack #Trend Micro
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 06 May 2026 07:50:51 +0000
════════════════════════
⌗ Tags: #Malware #AWS #Credential Harvester #DevSecOps #eBPF #GitHub Security #Kubernetes #Linux malware #malware analysis #QLNX #Quasar Linux #rootkit #supply chain attack #Trend Micro
Penetration Testing Tools
Quasar Linux (QLNX) Emerges to Subvert the Global Software Supply Chain
The novel Linux implant, Quasar Linux, poses a formidable threat not merely to individual workstations but to the
⤷ Title: 9.8 Severity Alert: Malicious Git Branches Can Hijack Your WebdriverIO Build Servers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 02:30:02 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BrowserStack #CI/CD security #Command Injection #CVE_2026_25244 #DevOps #GitHub Security #infosec #rce #supply chain attack #Test Automation #WebdriverIO
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Wed, 13 May 2026 02:30:02 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #BrowserStack #CI/CD security #Command Injection #CVE_2026_25244 #DevOps #GitHub Security #infosec #rce #supply chain attack #Test Automation #WebdriverIO
Daily CyberSecurity
9.8 Severity Alert: Malicious Git Branches Can Hijack Your WebdriverIO Build Servers
Critical Alert: CVE-2026-25244 (CVSS 9.8) in WebdriverIO allows RCE via unsanitized git branch names. Secure your CI/CD pipeline and update to 9.24.0 now.
⤷ Title: Critical Security Defect Exploits NTFS Processing Architecture Within 7-Zip
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 04:42:21 +0000
════════════════════════
⌗ Tags: #Vulnerability #7_Zip 26.01 download #7_Zip CVE_2026_48095 patch #dynamic link library memory corruption #GitHub Security Lab GHSL_2026_140 #heap buffer write overflow #NTFS archive handler #remote code execution vulnerability #signature based fallback detection #vtable hijack exploit #Yaroslav Lobachevsky cyber security
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 27 May 2026 04:42:21 +0000
════════════════════════
⌗ Tags: #Vulnerability #7_Zip 26.01 download #7_Zip CVE_2026_48095 patch #dynamic link library memory corruption #GitHub Security Lab GHSL_2026_140 #heap buffer write overflow #NTFS archive handler #remote code execution vulnerability #signature based fallback detection #vtable hijack exploit #Yaroslav Lobachevsky cyber security
Information Security News
7-Zip CVE-2026-48095 Patch: Fix Critical NTFS Code Execution
Update now to the 7-Zip CVE-2026-48095 patch. Discover how this critical heap overflow in the NTFS archive handler triggers remote code execution.
⤷ Title: Miasma Toolkit Targets Software Supply Chains
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Jun 2026 03:55:29 +0000
════════════════════════
⌗ Tags: #Malware #AI Coding Tools #cybersecurity #DevSecOps #GitHub Security #Miasma #NPM Malware #supply chain attack
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Fri, 12 Jun 2026 03:55:29 +0000
════════════════════════
⌗ Tags: #Malware #AI Coding Tools #cybersecurity #DevSecOps #GitHub Security #Miasma #NPM Malware #supply chain attack
Information Security News
Miasma Toolkit Threatens Software Supply Chains
Researchers uncover Miasma, a supply chain attack toolkit spreading via GitHub that steals credentials, infects packages, and hijacks AI coding tools.
⤷ Title: AgentBaiting Malware Campaign Targets AI MCP Servers
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 14:24:56 +0000
════════════════════════
⌗ Tags: #Malware #AgentBaiting #AI Malware #GitHub Security #MCP Server #StealC
════════════════════════
𐀪 Author: Nam Phong
════════════════════════
ⴵ Time: Thu, 23 Jul 2026 14:24:56 +0000
════════════════════════
⌗ Tags: #Malware #AgentBaiting #AI Malware #GitHub Security #MCP Server #StealC
Information Security News
AgentBaiting Malware Campaign Targets AI MCP Servers
Emergence of AgentBaiting Threat Vector The surging popularity of artificial intelligence tools has transformed skill directories into lucrative initial access points. Attackers target Model Conte…