#repo


Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo

Aug 11, 2026 // 17:30

Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one […]

Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data

Jul 7, 2026 // 18:21

A public issue can trick GitHub Agentic Workflows into leaking the contents of an organization’s private repositories, researchers at Noma Security have shown. The attacker […]

Clean GitHub repo tricks AI coding agents into running malware

Jun 27, 2026 // 17:36

An agentic coding tool tasked with running a seemingly benign GitHub repository could execute a malicious payload that is invisible to both security agents and […]

GitHub links repo breach to TanStack npm supply-chain attack

May 21, 2026 // 10:36

GitHub says the hackers who breached 3,800 internal repositories gained access via a malicious version of the Nx Console VS Code extension, compromised in last […]

⚡ Weekly Recap: Exchange 0-Day, npm Worm, Fake AI Repo, Cisco Exploit and More

May 18, 2026 // 18:10

Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A […]

Fake OpenAI Privacy Filter Repo Hits #1 on Hugging Face, Draws 244K Downloads

May 11, 2026 // 12:02

A malicious Hugging Face repository managed to take a spot in the platform’s trending list by impersonating OpenAI’s Privacy Filter open-weight model to deliver a […]

Bing AI Recommends Fake OpenClaw Repo Hiding Info-Stealing Malware

Mar 6, 2026 // 01:52

Researchers have discovered that Microsoft Bing’s AI-powered search was recommending a malicious GitHub repository for OpenClaw, a popular open-source AI agent. This allowed threat actors to distribute info-stealing […]