Stolen OAuth User Tokens used in Data Breach

Stolen OAuth User Tokens used in Data Breach

GitHub has investigated a security incident that uncovered abused stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and Travis-CI, to download data from dozens of organizations, including npm.…
GIT Operations Need 2FA

GIT Operations Need 2FA

GitHub is urging its base of users to enable two-factor authentication as the platform shakes up how it protects accounts from compromise.GitHub stopped accepting account passwords when authenticating Git operations.…
PyPi has a Critical Vulnerability

PyPi has a Critical Vulnerability

The operators of the official Python Package Index (PyPI) repository has eliminated 8 libraries that contain malicious code. The developers of PyPI have recently fixed the 3 most severe vulnerabilities,…

GitHub PoC Stingent Policies

GitHub announced their updated community guidelines that explain how the company will deal with exploits and malware samples hosted on their service. Security researcher uploaded the sample of ProxyLogon Vulnerability…