Trending

    GitHub suffers major breach exposing 3,800 internal repositories

    By A47 News Editorial Team·High6 articles covering this·5 news sources·Updated an hour ago·World
    Share:
    GitHub logo with a security breach alert graphic

    Here's what it means for you.

    This incident highlights critical vulnerabilities in software supply chains that could impact organizations globally.

    What happened

    Hackers accessed and stole around 3,800 internal repositories from GitHub through a poisoned VS Code extension.

    The Context

    • The breach was attributed to the threat group TeamPCP, also known as UNC6780.
    • GitHub stated that there is no evidence of customer data theft outside its internal repositories.
    • The incident occurred amid a broader wave of supply chain attacks targeting software development tools.

    Takeaway

    Organizations must enhance their security measures around third-party software and internal tools to prevent similar breaches in the future.

    6 Articles
    VentureBeat

    GitHub confirms 3,800 internal repos stolen through poisoned VS Code extension as supply chain worm hits Microsoft’s Python SDK

    GitHub confirmed that approximately 3,800 internal repositories were compromised due to a poisoned VS Code extension installed on an employee's device. The threat group TeamPCP, also known as UNC6780, has claimed responsibility for the breach and is ...

    11 hours ago
    Read Full Article
    The Next Web — Neural

    GitHub confirms hackers stole thousands of internal code repositories after employee installed a poisoned VS Code extension

    GitHub confirmed that approximately 3,800 internal repositories were stolen by hackers after an employee installed a malicious Visual Studio Code extension, marking a significant breach for the platform. The cybercrime group TeamPCP has claimed respo...

    14 hours ago
    Read Full Article
    TechCrunch

    GitHub says hackers stole data from thousands of internal repositories

    GitHub has confirmed that hackers stole approximately 3,800 internal repositories after an employee installed a malicious Visual Studio Code extension. The company is currently investigating the breach, which has raised concerns about the security of...

    15 hours ago
    Read Full Article
    Techmeme

    GitHub confirms ~3,800 internal repositories were breached after one of its employees installed a malicious VS Code extension; TeamPCP claims responsibility (Sergiu Gatlan/BleepingComputer)

    GitHub has confirmed that approximately 3,800 internal repositories were breached after an employee installed a malicious Visual Studio Code extension, with the cybercrime group TeamPCP claiming responsibility for the attack. This incident raises sig...

    20 hours ago
    Read Full Article
    Cointelegraph

    GitHub investigates unauthorized access to internal repositories

    GitHub is currently investigating unauthorized access to approximately 3,800 of its internal repositories, which involved the exfiltration of sensitive data. The company has taken steps to remove the malicious code extension that facilitated this bre...

    Techmeme

    GitHub says it's investigating "unauthorized access" to its internal repositories, and there's no proof of customer data outside its repositories being impacted (@github)

    GitHub is currently investigating unauthorized access to its internal repositories, stating that there is no evidence of customer data being affected outside these repositories. The company is taking this matter seriously as it seeks to understand th...