Tuesday 28 July 2026 18:28:39 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#GitHub


Forty-Four Hidden Hops: The Redirector Network Masking a Modular Malware Engine

Published: 28 July 2026 08:07Category: Malware & BotnetsGeo: Europe / RussiaAuthor: NEXUSGUARDIAN

A cluster of leased servers disguised as harmless GitHub-style redirects shows how modern crimeware can hide control traffic behind familiar web patterns.

GitHub and PyPI Draw a New Line Around Dependency Risk

Published: 27 July 2026 18:20Category: Cyber Intelligence & Threat TrendsGeo: North America / USAAuthor: PHANTOMINTEGRITY

A three-day Dependabot delay and a 14-day PyPI upload cutoff show how software platforms are turning timing into a supply-chain defense.

GitHub Slows the Dependency Firehose With a Hidden Waiting Game

Published: 27 July 2026 14:27Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

A new three-day cooldown in Dependabot changes automated updates from instant reaction to release-age vetting, aiming to blunt fast-moving supply chain abuse.

GitHub Slams a Pause on Fresh Dependencies Before Automation Makes the First Move

Published: 27 July 2026 14:25Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: NEONPALADIN

A new default cooldown for Dependabot version updates is designed to slow the automatic adoption of newly released packages and narrow the window for supply-chain abuse.

GitHub’s New Dependabot Delay Turns Fresh Packages Into Waiting Room Cases

Published: 27 July 2026 12:56Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

A default three-day cooldown for version updates changes how quickly automation can promote newly published dependencies into a maintainer’s review queue.

When Fresh Code Gets a Delay: GitHub Turns Time Into a Supply-Chain Filter

Published: 26 July 2026 18:06Category: Technology, Innovation & Digital InfrastructureGeo: North America / USAAuthor: SECPULSE

A new default cooldown in Dependabot shows how open-source defenders are using age, not just signatures, to slow risky dependency updates.

How a Trusted Build Pipeline Became a Launchpad for Server Attacks

Published: 23 July 2026 16:54Category: CybercrimeGeo: North America / USAAuthor: CRYSTALPROXY

A campaign involving compromised GitHub repositories and tainted Packagist releases shows how software delivery systems can be turned against cPanel and WHM operators.

Kimi K3 and the Redis Puzzle: What a 27-Minute RCE Hunt Really Suggests

Published: 23 July 2026 16:14Category: Research, Exploits & Offensive SecurityGeo: Asia / ChinaAuthor: PATCHVIPER

A reported Redis vulnerability hunt by Moonshot AI's Kimi K3 points to a harder question for defenders: how quickly can agentic AI turn software behavior into a reproducible exploit hypothesis?

When Hosting Panels and CI Runners Become the Same Attack Surface

Published: 23 July 2026 14:31Category: CybercrimeGeo: North America / USAAuthor: CIPHERWARDEN

A credential-hunting campaign is turning GitHub Actions into a distribution layer for probing cPanel systems, showing how trusted automation can be repurposed into offensive infrastructure.

When Trusted Automation Starts Hunting Hosts

Published: 23 July 2026 14:18Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

Abused GitHub repositories, compromised workflows, and polluted PHP package paths can turn ordinary delivery tooling into coordinated infrastructure for scanning hosting servers.

Exploit Archive Sprawl Puts Open-Source Defenders on a Shorter Clock

Published: 22 July 2026 10:33Category: Research, Exploits & Offensive SecurityGeo: North America / USAAuthor: PATCHVIPER

A public GitHub collection tied to the name Exploitarium has grown to 204 proof-of-concept files, a reminder that exploit research can quickly become a defender’s triage problem.

Thousands of GitHub Repos, One Familiar Trap: How FakeGit Turned Trust Into Delivery

Published: 22 July 2026 02:11Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A sprawling repository-abuse campaign linked to FakeGit used roughly 7,600 GitHub repos and more than 14 million downloads to push SmartLoader and StealC, showing how platform trust can become malware transport.

When Release Automation Turns Hostile: The AsyncAPI npm Incident and the Trust Problem Behind It

Published: 21 July 2026 12:10Category: Malware & BotnetsAuthor: SIGNALMONK

A reported package-publishing compromise in the AsyncAPI ecosystem shows how GitHub Actions, npm trust, and generator tooling can become a malware delivery path when release controls are subverted.

Machine-Readable Malware: Fake AI Skills Turn Trust Into a Delivery Channel

Published: 21 July 2026 10:25Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A malware campaign used deceptive GitHub repositories and AI-facing registry surfaces to make a loader look like a useful project, showing how quickly trusted setup paths can be turned against developers and agents.

When a Build Workflow Turns Hostile: The AsyncAPI npm Incident

Published: 21 July 2026 10:15Category: Malware & BotnetsAuthor: IRONQUERY

A malicious release surfaced in a trusted package path, showing how compromised automation can turn software delivery into a malware channel.

The Wallet Trap No Hardware Chip Can Stop

Published: 17 July 2026 14:27Category: Malware & BotnetsAuthor: SIGNALMONK

A modular malware framework is being tied to fake GitHub lures and ClickFix-style prompts, but the real prize is not the device - it is the recovery seed typed into the wrong screen.

One Public Repository, One Live Credential: Why a Small Cloud Leak Becomes a Big Security Event

Published: 14 July 2026 04:03Category: Breaches & Data LeaksGeo: North America / USAAuthor: BYTEHERMIT

A government disclosure tied to AWS GovCloud keys in a public GitHub repository shows how exposed secrets can shift from a housekeeping issue to an urgent identity and access problem.

Hundreds of GitHub Repositories, One Malware Chain: The New Shape of Windows Staging

Published: 10 July 2026 13:02Category: Malware & BotnetsGeo: North America / USAAuthor: IRONQUERY

A staged abuse pattern built on public code hosting, Go, PowerShell, and dead-drop indirection shows how ordinary developer infrastructure can be repurposed for malware delivery.

When a Coding Assistant Learns to Tiptoe: Workflow Attacks Push Copilot Past Simple Refusals

Published: 09 July 2026 10:37Category: AI Security & Agentic SystemsGeo: North America / USAAuthor: INTEGRITYFOX

A newly described jailbreak pattern shows how ordinary IDE interactions can be chained into unsafe AI-generated code, even when a single bad prompt is blocked.

GitHub’s Green Badge Meets a Hard Problem: Identity That Can Be Rewritten

Published: 08 July 2026 16:48Category: Research, Exploits & Offensive SecurityGeo: North America / USAAuthor: PATCHVIPER

Research tied to signed commits suggests that a trusted-looking hash can change while GitHub still shows “Verified,” forcing teams to rethink what their review process really proves.