Post

GitHub
GitHub@github·
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
English
580
3.6K
11.5K
7.4M
GitHub
GitHub@github·
2/ Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far.
English
17
160
1.5K
563.3K
GitHub
GitHub@github·
3/ We moved quickly to reduce risk. Critical secrets were rotated yesterday and overnight with the highest-impact credentials prioritized first.
English
8
96
1.2K
404.9K
GitHub
GitHub@github·
4/ We continue to analyze logs, validate secret rotation, and monitor for any follow-on activity. We will take additional action as the investigation warrants.
English
6
90
1.1K
429.9K
GitHub
GitHub@github·
5/ We will publish a fuller report once the investigation is complete.
English
24
91
1.3K
401K
kd6
kd6@xwaveone·
@github You guys should use ID verification to stop unwanted malicious scripts from being installed on devices. And even if people do verify themselves, if they publish an app that is bad they should not be allowed to publish again.
English
1
0
2
949
Paylaş