GitHub - Tagged - Security Boulevard The Home of the Security Bloggers Network Tue, 26 Mar 2024 19:37:21 +0000 en-US hourly 1 https://wordpress.org/?v=6.4.3 https://securityboulevard.com/wp-content/uploads/2021/10/android-chrome-256x256-1-32x32.png GitHub - Tagged - Security Boulevard 32 32 133346385 Complex Supply Chain Attack Targets GitHub Developers https://securityboulevard.com/2024/03/complex-supply-chain-attack-targets-github-developers/ Tue, 26 Mar 2024 18:42:46 +0000 https://securityboulevard.com/?p=2013043 supply chain, SBOM, cybersecurity, SLSA organizations third party attacks supply chain supply chain ransomware The Kill Chain Model

Unidentified threat actors used multiple tactics to launch a sophisticated software supply-chain campaign targeting developers on the GitHub platform, including members of the popular Top.gg community that includes more than 170,000 members. The attackers used a range of tactics and techniques, from leveraging stolen browser cookies to take over accounts to contributing malicious code with..

The post Complex Supply Chain Attack Targets GitHub Developers appeared first on Security Boulevard.

]]>
2013043
Sentry, GitHub Use AI to Help Fix Coding Errors https://securityboulevard.com/2024/03/sentry-github-use-ai-to-help-fixing-coding-errors/ Thu, 21 Mar 2024 15:43:14 +0000 https://securityboulevard.com/?p=2012606 AI code fixing

Developers are getting more help detecting and addressing bugs in their code through new AI-based tools that Sentry.io and GitHub each introduced this week. Sentry unveiled the beta of Autofix, a feature that uses company’s machine learning and AI capabilities and is aimed at debugging errors in production by leveraging what the vendor knows about..

The post Sentry, GitHub Use AI to Help Fix Coding Errors appeared first on Security Boulevard.

]]>
2012606
GitHub Fights Forks — Millions of Them — Huge Software Supply Chain Security FAIL https://securityboulevard.com/2024/02/github-repo-confusion-supply-chain-richixbw/ Thu, 29 Feb 2024 16:37:11 +0000 https://securityboulevard.com/?p=2010508 A fork, wrapped in delicious pasta

Forking hell: Scrotebots clone thousands of projects, injecting malware millions of times.

The post GitHub Fights Forks — Millions of Them — Huge Software Supply Chain Security FAIL appeared first on Security Boulevard.

]]>
2010508
‘Extremely serious’ — Mercedes-Benz Leaks Data on GitHub https://securityboulevard.com/2024/01/mercedes-benz-leak-github-richixbw/ Tue, 30 Jan 2024 17:41:29 +0000 https://securityboulevard.com/?p=2007038 A Mercedes hood ornament

Oh, Lord: My friends all hack Porsches—I must make amends.

The post ‘Extremely serious’ — Mercedes-Benz Leaks Data on GitHub appeared first on Security Boulevard.

]]>
2007038
Attackers Finding Novel Ways to Abuse GitHub: ReversingLabs https://securityboulevard.com/2023/12/attackers-finding-novel-ways-to-abuse-github-reversinglabs/ Wed, 20 Dec 2023 21:57:26 +0000 https://securityboulevard.com/?p=2002687 AI code fixing

Threat actors are finding new ways to take advantage of GitHub in hopes of tricking developers into putting malicious code into their software and sending to users downstream, according to researchers with ReversingLabs. Code repositories like GitHub and Python Package Index (PyPI) are popular targets for hackers who want to abuse the software supply chain..

The post Attackers Finding Novel Ways to Abuse GitHub: ReversingLabs appeared first on Security Boulevard.

]]>
2002687
NSA Releases EliteWolf GitHub Repository for Securing OT Environments https://securityboulevard.com/2023/10/nsa-releases-elitewolf-github-repository-for-securing-ot-environments/ Fri, 13 Oct 2023 16:03:10 +0000 https://securityboulevard.com/?p=1992361 NSA cybersecurity OT

The National Security Agency released a code repository in GitHub to make it easier for critical infrastructure organizations and similar entities to better identify and detect potentially malicious activities in their operational technology (OT) environments. The agency announced this week that it released the repository for OT Intrusion Detection Signatures and Analytics to the NSA..

The post NSA Releases EliteWolf GitHub Repository for Securing OT Environments appeared first on Security Boulevard.

]]>
1992361
Biggest GitHub code security threats | Software Supply Chain Security | Contrast Security https://securityboulevard.com/2023/10/biggest-github-code-security-threats-software-supply-chain-security-contrast-security/ Thu, 12 Oct 2023 20:54:42 +0000 https://www.contrastsecurity.com/security-influencers/biggest-github-code-security-threats-software-supply-chain-security-contrast-security Biggest GitHub code security threats | Software Supply Chain Security | Contrast Security

GitHub is the Megladon of source code hosts, and as such, it sports a gargantuan bulls-eye that flashes neon to hackers looking to poison the software supply chain.  

The post Biggest GitHub code security threats | Software Supply Chain Security | Contrast Security appeared first on Security Boulevard.

]]>
1992373
GitHub Repositories Victimized Amid Supply Chain Attack                 https://securityboulevard.com/2023/10/github-repositories-victimized-amid-supply-chain-attack/ Thu, 12 Oct 2023 09:00:15 +0000 https://tuxcare.com/?p=13511 In a digital landscape rife with vulnerabilities, a recent and disconcerting phenomenon has come to light. GitHub repositories, the foundation of numerous software projects, have been victimized by a devious supply chain attack. This well-planned supply chain attack on GitHub repositories, found in July 2023, involved the hacking of GitHub accounts as well as the […]

The post GitHub Repositories Victimized Amid Supply Chain Attack                 appeared first on TuxCare.

The post GitHub Repositories Victimized Amid Supply Chain Attack                 appeared first on Security Boulevard.

]]>
1997940
Beware: WinRAR Vulnerability PoC Exposed https://securityboulevard.com/2023/10/beware-winrar-vulnerability-poc-exposed/ Wed, 04 Oct 2023 09:00:33 +0000 https://tuxcare.com/?p=13396 A hacker recently posted a fake proof-of-concept (PoC) exploit for a previously patched WinRAR vulnerability, which is a concerning revelation. The goal of this malevolent operation was to infect unsuspecting downloaders with the infamous VenomRAT virus. While the immediate threat has been mitigated, this incident highlights the risks of simply accepting PoCs obtained from services […]

The post Beware: WinRAR Vulnerability PoC Exposed appeared first on TuxCare.

The post Beware: WinRAR Vulnerability PoC Exposed appeared first on Security Boulevard.

]]>
1997977
Cybersecurity Insights with Contrast CISO David Lindner | 9/29 https://securityboulevard.com/2023/09/cybersecurity-insights-with-contrast-ciso-david-lindner-9-29/ Fri, 29 Sep 2023 13:00:00 +0000 https://www.contrastsecurity.com/security-influencers/cybersecurity-insights-with-contrast-ciso-david-lindner-9/15-1 Cybersecurity Insights with Contrast CISO David Lindner | 9/29

Insight #1

For years — since 2018 — the National Institute of Standards and Technology (NIST) has said that password length trumps password complexity requirements. Now LastPass is
forcing users into choosing a longer password. This is a brilliant move. More companies should
force long passwords (12 characters or more) by default.

The post Cybersecurity Insights with Contrast CISO David Lindner | 9/29 appeared first on Security Boulevard.

]]>
1990992