Microsoft shut down dozens of GitHub code repositories for Azure and AI coding tools after a reported hack.
Microsoft is exposed to a new security risk as hackers may have managed to place malware inside some of its open-source ...
Hackers infiltrated Microsoft's open-source projects on GitHub, embedding password-stealing malware into the code, prompting ...
VS Code flaw exposes GitHub OAuth tokens via one-click attack on GitHub.dev, enabling private repo access and token theft.
A VS Code vulnerability in GitHub.dev lets attackers steal full GitHub OAuth tokens via a single malicious link, exposing all private repositories.
The Miasma credential-stealing attack framework, which has recently targeted open-source ecosystems through supply-chain ...
GitHub is just the latest victim of TeamPCP, a gang that has carried out a spree of software supply chain attacks that has impacted hundreds of organizations.