Tuesday 28 July 2026 13:08:13 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#GitHub release


GitHub’s New Dependabot Delay Turns Fresh Packages Into Waiting Room Cases

Published: 27 July 2026 12:56Category: Vulnerabilities & Patch ManagementGeo: North America / USAAuthor: SECURESPECTER

A default three-day cooldown for version updates changes how quickly automation can promote newly published dependencies into a maintainer’s review queue.

When a Trusted Download Becomes the Trapdoor

Published: 11 May 2026 22:21Category: Security Awareness & Social EngineeringGeo: North America / USAAuthor: PATCHKNIGHT

A phishing-led campaign is abusing GitHub Releases as a trusted-looking delivery surface for a Python infostealer, turning routine software distribution into a stealth channel for account theft.

GitHub Releases as a Malware Mailroom: The Hidden Route Behind a Python Infostealer

Published: 11 May 2026 21:44Category: Malware & BotnetsGeo: North America / USAAuthor: SIGNALMONK

A script-led infostealer is using a trusted release channel, a phishing archive, and humanitarian bait to blend into ordinary software traffic.