CVE-2026-3854 GitHub flaw enables remote code executionSecurity Affairs·Apr 28, 20:44 UTC · Apr 28, 2026VulnerabilityCVE-2026-385460
GitHub fixed a new critical flaw in the GitHub Enterprise ServerSecurity Affairs·Aug 22, 07:08 UTC · Aug 22, 2024VulnerabilityCVE-2024-6800CVE-2024-7711CVE-2024-6337+1 CVEs160
GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal ReposThe Hacker News·May 20, 16:10 UTC · May 20, 2026Data breach60
AWS CodeBuild Misconfiguration Exposed GitHub Repos to Potential Supply Chain AttacksThe Hacker News·Jan 15, 00:00 UTC · Jan 15, 2026Exploit / PoC in the wild60
GitHub Breach Traced to Malicious ‘Nx Console’ VS Code ExtensionInfosecurity Magazine·May 21, 14:45 UTC · May 21, 2026Data breachCVE-2026-48027160
Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git PushThe Hacker News·Apr 28, 18:19 UTC · Apr 28, 2026VulnerabilityCVE-2026-3854160
Users of JetBrains IDEs at risk of GitHub access token compromise (CVE-2024-37051)Help Net Security·Jun 11, 00:00 UTC · Jun 11, 2024Vulnerability in the wildCVE-2024-3705160
GitHub addressed a critical vulnerability in Enterprise ServerSecurity Affairs·Oct 16, 06:45 UTC · Oct 16, 2024VulnerabilityCVE-2024-9487CVE-2024-4985CVE-2024-9539160
Veza integrates with GitHub to secure customers’ dataHelp Net Security·Feb 10, 00:00 UTC · Feb 10, 2023Data breach160
GitHub rolls out new token scanning, security alert featuresCyberScoop·Oct 17, 20:26 UTC · Oct 17, 2018Exploit / PoC in the wild60
GitHub says internal repositories were impacted in poisoned VS Code extension attackCyberScoop·May 20, 16:59 UTC · May 20, 2026Ransomware60
TeamPCP breached GitHub's internal codebase via poisoned VS Code extensionHelp Net Security·May 20, 00:00 UTC · May 20, 2026Data breach60
GitHub Action Compromise Puts CI/CD Secrets at Risk in Over 23,000 RepositoriesThe Hacker News·Mar 18, 04:03 UTC · Mar 18, 2025VulnerabilityCVE-2025-30066CVE-2023-49291160
JetBrains fixed IntelliJ IDE flaw exposing GitHub access tokensSecurity Affairs·Jun 12, 10:24 UTC · Jun 12, 2024Exploit / PoC in the wildCVE-2024-37051160
GitHub Confirms Breach of Internal RepositoriesInfosecurity Magazine·May 20, 10:45 UTC · May 20, 2026Ransomware60
Number of incidents affecting GitHub, Bitbucket, GitLab, and Jira continues to riseHelp Net Security·Aug 7, 00:00 UTC · Aug 7, 2024RansomwareCVE-2021-22205160
Critical GitHub Enterprise Server Auth Bypass bug. Fix it now!Security Affairs·May 22, 10:05 UTC · May 22, 2024VulnerabilityCVE-2024-4985160
GitHub revamps bug bounty program with new VIP tier, payout changesHelp Net Security·Jul 23, 00:00 UTC · Jul 23, 2026Exploit / PoC160
GitHub Rotates Keys After High-Severity Vulnerability Exposes CredentialsThe Hacker News·Jan 17, 10:00 UTC · Jan 17, 2024Vulnerability in the wildCVE-2024-0200CVE-2024-0507160
GitHub Updates Policy to Remove Exploit Code When Used in Active AttacksThe Hacker News·Jun 5, 17:01 UTC · Jun 5, 2021Exploit / PoC in the wild60
GitHub Internal Repositories Breached via Malicious Nx Console VS Code ExtensionThe Hacker News·May 28, 05:34 UTC · May 28, 2026Data breach in the wildCVE-2026-45321CVE-2026-4802760
U.S. CISA adds Fortinet FortiOS/FortiProxy and GitHub Action flaws to its Known Exploited Vulnerabilities catalogSecurity Affairs·Mar 20, 14:17 UTC · Mar 20, 2025Exploit / PoC in the wildCVE-2025-24472CVE-2025-30066CVE-2024-5559160
GitHub Token Leak Exposes Python's Core Repositories to Potential AttacksThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2024Exploit / PoC in the wild160
GitHub Fixes Maximum Severity Flaw in Enterprise ServerInfosecurity Magazine·May 23, 10:15 UTC · May 23, 2024VulnerabilityCVE-2024-4985160
GitHub fixes maximum severity Enterprise Server auth bypass bug (CVE-2024-4985)Help Net Security·May 23, 00:00 UTC · May 23, 2024VulnerabilityCVE-2024-4985160
Malicious Actors Exploit GitHub to Distribute Fake ExploitsInfosecurity Magazine·Jun 14, 17:00 UTC · Jun 14, 2023Exploit / PoC60
SAP-Related npm Packages Compromised in CredentialThe Hacker News·Apr 30, 16:39 UTC · Apr 30, 2026Data breach60
Trivy Hack Spreads Infostealer via Docker, Triggers Worm and Kubernetes WiperThe Hacker News·Mar 25, 14:32 UTC · Mar 25, 2026MalwareCVE-2026-33634160
Over 600 Laravel Apps Exposed to Remote Code Execution Due to Leaked APP_KEYs on GitHubThe Hacker News·Jul 15, 00:00 UTC · Jul 15, 2025Vulnerability in the wildCVE-2018-15133CVE-2024-5555660
GitHub patches critical vulnerability in its Enterprise ServersCyberScoop·Oct 16, 20:24 UTC · Oct 16, 2024VulnerabilityCVE-2024-9487CVE-2024-4985CVE-2024-9539160
Critical GitHub Enterprise Server auth bypass flaw fixed (CVE-2024-6800)Help Net Security·Aug 22, 00:00 UTC · Aug 22, 2024VulnerabilityCVE-2024-680060
GitHub removes researcher's Exchange Server exploit, sparking industry debateCyberScoop·Mar 11, 21:25 UTC · Mar 11, 2021Exploit / PoC in the wild60
GitHub hit with record 1.35-Tbps denial of service attack, more attacks expectedCyberScoop·Mar 1, 19:17 UTC · Mar 1, 2018Exploit / PoC in the wild160
⚡ Weekly Recap: AI-Powered Phishing, Android Spying Tool, Linux Exploit, GitHub RCE & MoreThe Hacker News·May 5, 05:41 UTC · May 5, 2026Vulnerability in the wildCVE-2026-41940CVE-2026-31431CVE-2026-3854+2 CVEs160
Multiple Git flaws led to credentials compromiseSecurity Affairs·Jan 27, 14:36 UTC · Jan 27, 2025VulnerabilityCVE-2025-23040CVE-2024-53263CVE-2024-52006+1 CVEs60
GitHub Patches Critical Flaw in Enterprise Server Allowing Unauthorized Instance AccessThe Hacker News·Oct 15, 00:00 UTC · Oct 15, 2024VulnerabilityCVE-2024-9487CVE-2024-4985CVE-2024-9539+1 CVEs60
GitHub Patches Critical Security Flaw in Enterprise Server Granting Admin PrivilegesThe Hacker News·Aug 22, 04:48 UTC · Aug 22, 2024VulnerabilityCVE-2024-6800CVE-2024-7711CVE-2024-6337+1 CVEs160
Massive GitHub analysis reveals 10 million secrets hidden in 1 billion commitsHelp Net Security·Mar 9, 00:00 UTC · Mar 9, 2023Data breach160
How GitHub untangled itself from the ‘Octopus’ malware that infected 26 software projectsCyberScoop·May 29, 19:51 UTC · May 29, 2020Malware in the wild160