github

Mozilla、情報漏洩を受けてFirefoxリリースのGPG署名鍵を更新 News

Mozilla、情報漏洩を受けてFirefoxリリースのGPG署名鍵を更新

Mozillaは本日、GitHub上で誤って公開されてしまったFirefoxおよびThunderbirdのリリースに署名するために使用されるGPG鍵を更新したと発表した。 しかし、月曜日のブログ記事では、GitHubのリポジトリにアクセスで...
GitHub, PyPI add time-absed defenses against supply chain attacks News

GitHub, PyPI add time-absed defenses against supply chain attacks

GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management to...
「FakeGit」キャンペーンは、7,600のGitHubリポジトリを利用してSmartLoaderマルウェアを拡散している News

「FakeGit」キャンペーンは、7,600のGitHubリポジトリを利用してSmartLoaderマルウェアを拡散している

「FakeGit」と名付けられた大規模な攻撃キャンペーンでは、7,600件の悪意あるGitHubリポジトリを通じて、SmartLoaderおよびStealCマルウェアが拡散されており、そのダウンロード数は1,400万回以上に達した。 800...
認証情報を盗むマルウェアに感染したAsyncAPIのnpmパッケージ News

認証情報を盗むマルウェアに感染したAsyncAPIのnpmパッケージ

情報窃取機能を備えたリモートアクセストロイの木馬を配布するサプライチェーン攻撃により、AsyncAPI パッケージの悪意のあるバージョン5つが Node Package Manager (npm) に公開されました。 攻撃者は、設定ミスのあ...
300件近くのGitHubリポジトリが、正規のソフトウェアを装ってマルウェアを拡散させている News

300件近くのGitHubリポジトリが、正規のソフトウェアを装ってマルウェアを拡散させている

ある脅威アクターが、正規のソフトウェアやセキュリティプロジェクトを装った何百もの偽のGitHubリポジトリを公開し、情報窃取型マルウェアを拡散させている。 このキャンペーンは、セキュリティ製品、仮想通貨サービス、金融ツール、開発者向けユーテ...
Clean GitHub repo tricks AI coding agents into running malware News

Clean GitHub repo tricks AI coding agents into running malware

An agentic coding tool tasked with cloning and setting up a seemingly benign GitHub repository could execute a malicious...
GitHub、サプライチェーン攻撃に対処するためのnpmのセキュリティ変更を発表 News

GitHub、サプライチェーン攻撃に対処するためのnpmのセキュリティ変更を発表

GitHubは、来月リリース予定のnpm v12において、「npm install」コマンドによって引き起こされる動作を悪用したサプライチェーン攻撃を阻止することを目的とした、セキュリティに重点を置いたいくつかの変更が導入されると発表しまし...
GitHub、パスワード窃取マルウェアを配布するMicrosoftのリポジトリを無効化 News

GitHub、パスワード窃取マルウェアを配布するMicrosoftのリポジトリを無効化

マイクロソフトは、GitHub上のAzure、microsoft、Azure-Samples、およびMicrosoftDocsの各組織にまたがる73のリポジトリを削除し、継続的インテグレーションのパイプラインに支障をきたした。 この事象は6...
VS Code zero-day lets hackers steal GitHub tokens in one click News

VS Code zero-day lets hackers steal GitHub tokens in one click

A security researcher has released exploit code for a Visual Studio Code (VS Code) zero-day vulnerability that allows at...
GitHub links repo breach to TanStack npm supply-chain attack News

GitHub links repo breach to TanStack npm supply-chain attack

GitHub says the hackers who breached 3,800 internal repositories gained access via a malicious version of the Nx Console...