A recent cyberattack targeting GitHub repositories has been uncovered, where malicious commits were introduced into several open-source projects. The attack was orchestrated to frame a well-known security researcher by making it appear as though they were responsible for injecting malicious code and distributing malware. By gaining unauthorized access to multiple repositories, the attackers manipulated commit histories to include harmful code, aiming to tarnish the researcher’s reputation within the cybersecurity community. The method employed involved compromising GitHub accounts to inject unauthorized commits into open-source projects. These commits contained malicious payloads, which were stealthily embedded into the repositories’ histories, often going unnoticed by maintainers. The attack was meticulously planned to mislead observers into believing that the targeted researcher was behind the malicious activity. The intent appeared to be creating confusion, eroding trust, and damaging the researcher’s credibility. This incident underscores the vulnerability of collaborative development platforms, particularly in the open-source ecosystem, where contributors often have varying levels of access and oversight. GitHub has responded to the incident by launching an investigation and implementing measures to prevent similar attacks. Developers are being advised to carefully review commit histories and pull requests for any unauthorized changes. The attack highlights the risks inherent in collaborative development platforms, where threat actors can exploit weaknesses to inject malicious code or manipulate trust within the community. It serves as a critical reminder of the need for robust security practices, such as enabling two-factor authentication (2FA), conducting regular audit trails, and thoroughly vetting contributions, to protect the integrity of open-source projects.
A broken access control vulnerability in Keycloak, tracked as CVE-2026-17059, allows restricted administrator accounts to access users' personal information through the Admin R...
Bitsight has revealed details of Fuyao, a campaign that allegedly exploits low-cost Android TV boxes for advertising fraud and proxy services. Researchers found that some devices w...
Security researchers have disclosed 84 vulnerabilities affecting 4G and 5G core network implementations, exposing mobile network infrastructure to serious attacks such as session h...