github 17
- Laravel-Lang Packages Poisoned to Exfiltrate CI Secrets
- Megalodon Supply Chain Attack Infects 5,500+ GitHub Repositories
- Packagist Supply Chain Attack Injects Linux Malware Into 8 Composer Packages
- Megalodon GitHub Attack Injects Malicious CI/CD Workflows into 5,561 Repos
- Grafana Codebase Stolen via TanStack Supply Chain Attack
- GitHub Confirms 3,800 Internal Repos Breached via Malicious VS Code Extension
- Grafana Labs Source Code Exposed via GitHub Breach Linked to TanStack npm Attack
- GitHub Actions Supply Chain Attack Hijacks actions-cool/issues-helper Tags
- Official Checkmarx Jenkins AST Plugin Backdoored with Infostealer
- Google Patches CVSS 10 Gemini CLI RCE Enabling Supply-Chain Code Execution
- Wiz Used AI Reverse Engineering to Uncover High-Severity GitHub Vulnerability
- GitHub RCE Flaw CVE-2026-3854 Exposed Millions of Private Repositories
- Critical GitHub RCE CVE-2026-3854 Exposed Millions of Repositories
- Checkmarx Confirms GitHub Repository Data Published on Dark Web After March Supply Chain Attack
- Comment and Control: Claude Code, Gemini CLI, and GitHub Copilot Vulnerable to Prompt Injection via Code Comments
- OpenAI Rotates macOS Code-Signing Certs After North Korea-Linked Axios Supply Chain Attack
- Microsoft Suspends Developer Accounts for High-Profile Open Source Projects