Briefing Findings · Attackers are using supply-chain style
Story-specific findings extracted from this briefing's coverage. Fast Facts in the sidebar holds the canonical reference data (CEO, founded, ticker).
What to Watch
-
Use GitHub guidance to check for compromised CI/CD workflows and bot-like maintenance changes in your repos.
BleepingComputer
-
Review whether your org’s developer tooling includes known-bad or recently updated VS Code extensions tied to reported breaches.
guru3d.com
What Changed
-
5,561 GitHub repos got malicious CI/CD commits injected in 6 hours. The commits looked exactly like routine bot maintenance. Here is what happened and how to check if you were hit.
BleepingComputer
-
Megalodon: Mass GitHub Repo Backdooring via CI Workflows
safedep.io
-
GitHub confirms breach of 3,800 repos via malicious VSCode extension
bleepingcomputer.com