
NextGenRails™
232 posts

NextGenRails™
@NextGenRails
Founder @ NextGenRails™ | Built https://t.co/12zRapuMNS · https://t.co/DwaE0fJ0ks · https://t.co/gJR3lH1AP5 | Cryptographic compliance infrastructure | Trust is computed.



Supply chain attacks can’t be solved with one silver bullet. They need a systemic approach. For every dev layer (not just npm, but CI, Docker, and your editor) ask 4 questions: 1. How can we reduce dependencies? 2. Isolation 3. Update control 4. Review Thread ↓






We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.





1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.







‼️🚨 BREAKING: GitHub has been compromised by TeamPCP. GitHub has confirmed the internal breach. A poisoned VS Code extension on an employee device exfiltrated ~3,800 internal repositories. TeamPCP is already selling the data on a cybercrime forum.


1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.



