Post

GitHub
GitHub@github·
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
English
569
3.6K
11.4K
7.3M
GitHub
GitHub@github·
2/ Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far.
English
16
159
1.5K
557.1K
GitHub
GitHub@github·
3/ We moved quickly to reduce risk. Critical secrets were rotated yesterday and overnight with the highest-impact credentials prioritized first.
English
7
95
1.2K
399.9K
GitHub
GitHub@github·
4/ We continue to analyze logs, validate secret rotation, and monitor for any follow-on activity. We will take additional action as the investigation warrants.
English
5
89
1.1K
423.2K
Trundle the Great
Trundle the Great@NotRob6·
@github If it's a poisoned extension though, you'll have to do more, and likely have, or it's just a short matter of time...
English
0
0
2
8.3K
Oscar Mayer
Oscar Mayer@oscarmayer·
The Wienie 500 is back. Tune in at 2pm ET on FOX to see who will taste victory, cook the competition, and earn the title of top dog.
Oscar Mayer tweet media
English
35
71
689
2M
Anotida Msiiwa
Anotida Msiiwa@anomsiiwa·
@github Publishing the technical details this early is a good standard for the industry. Rotating those critical secrets overnight was the right move to limit the blast radius.
English
0
0
0
2.3K
Ammar
Ammar@_ammar_r·
@github Bro, can you stop spamming, you might get banned
English
0
0
0
2K
Geeक ✽
Geeक ✽@yatharthsingh·
@github Please confirm if customer data, repo is impacted or not
English
0
0
1
1.3K
Paylaş