#githubsecurity search results

Automate leak detection across all GitHub repositories at once with my script. Powered by Gitleaks. 🔗 nxtexploit.com/urls/5/ #GitHubSecurity #Gitleaks #BugBounty

nXtExploit's tweet image. Automate leak detection across all GitHub repositories at once with my script. Powered by Gitleaks.

🔗 nxtexploit.com/urls/5/

 #GitHubSecurity #Gitleaks #BugBounty

刚刚 GitHub 绑定的邮箱收到了一封钓鱼邮件,估计和最近领加密货币空投有关,反手举报了一波,然后开启了账号两步验证。#GitHubSecurity

JohnWmm's tweet image. 刚刚 GitHub 绑定的邮箱收到了一封钓鱼邮件,估计和最近领加密货币空投有关,反手举报了一波,然后开启了账号两步验证。#GitHubSecurity

Elevate your GitHub security! Understand the critical role of signed commits in protecting your intellectual property and ensuring code integrity. #GitHubSecurity #SignedCommits bit.ly/4dvZRxg

HarveyLevin4's tweet image. Elevate your GitHub security! Understand the critical role of signed commits in protecting your intellectual property and ensuring code integrity. #GitHubSecurity #SignedCommits bit.ly/4dvZRxg

GitHub has taken a significant step in enhancing security by enabling push protection by default for all public repositories, aiming to prevent inadvertent exposure of sensitive information like access tokens and API keys during code pushes. . #avmconsulting #GitHubSecurity

AvmConsulting's tweet image. GitHub has taken a significant step in enhancing security by enabling push protection by default for all public repositories, aiming to prevent inadvertent exposure of sensitive information like access tokens and API keys during code pushes.
.
#avmconsulting #GitHubSecurity

Fortifying GitHub against Repojacking: Insights into Attacks and Effective Countermeasures! DC: Afreen S, Muskaan Siddiqui, Lynda D, Kaustubh CC: Sharmila Ramraj #github #githubsecurity #repojacking #cybersecurity #codeprotection #opensource #securedevelopment

CyscomVit's tweet image. Fortifying GitHub against Repojacking: Insights into Attacks and Effective Countermeasures!   

DC: Afreen S, Muskaan Siddiqui, Lynda D, Kaustubh
CC: Sharmila Ramraj   

#github #githubsecurity #repojacking #cybersecurity #codeprotection #opensource #securedevelopment
CyscomVit's tweet image. Fortifying GitHub against Repojacking: Insights into Attacks and Effective Countermeasures!   

DC: Afreen S, Muskaan Siddiqui, Lynda D, Kaustubh
CC: Sharmila Ramraj   

#github #githubsecurity #repojacking #cybersecurity #codeprotection #opensource #securedevelopment
CyscomVit's tweet image. Fortifying GitHub against Repojacking: Insights into Attacks and Effective Countermeasures!   

DC: Afreen S, Muskaan Siddiqui, Lynda D, Kaustubh
CC: Sharmila Ramraj   

#github #githubsecurity #repojacking #cybersecurity #codeprotection #opensource #securedevelopment
CyscomVit's tweet image. Fortifying GitHub against Repojacking: Insights into Attacks and Effective Countermeasures!   

DC: Afreen S, Muskaan Siddiqui, Lynda D, Kaustubh
CC: Sharmila Ramraj   

#github #githubsecurity #repojacking #cybersecurity #codeprotection #opensource #securedevelopment

Criminals exploit GitHub's infrastructure for widespread malware delivery, as revealed by security researchers at Recorded Future. Stay vigilant online! 🔐 #GitHubSecurity #MalwareThreats #CyberSafety

cheinyeanlim's tweet image. Criminals exploit GitHub's infrastructure for widespread malware delivery, as revealed by security researchers at Recorded Future. Stay vigilant online! 🔐 #GitHubSecurity #MalwareThreats #CyberSafety

🚨 Alert! Critical flaw in GitHub Enterprise Server (GHES) allows unauthorized access. Patch immediately! 🔒 #GitHubSecurity #PatchNow Read more buff.ly/3KciJVv

iamnoahfranklin's tweet image. 🚨 Alert! Critical flaw in GitHub Enterprise Server (GHES) allows unauthorized access. Patch immediately! 🔒 #GitHubSecurity #PatchNow Read more  buff.ly/3KciJVv

A recent cascading supply chain attack linked to SpotBugs reveals how a stolen personal access token compromised GitHub Actions, impacting users like Coinbase and exposing major open-source vulnerabilities. 🔐⚠️ #GitHubSecurity #OpenSource link: ift.tt/G3WqvQ5

TweetThreatNews's tweet image. A recent cascading supply chain attack linked to SpotBugs reveals how a stolen personal access token compromised GitHub Actions, impacting users like Coinbase and exposing major open-source vulnerabilities. 🔐⚠️ #GitHubSecurity #OpenSource

link: ift.tt/G3WqvQ5

🚨 CRITICAL: astronomer dag-factory (<0.23.0a9) lets attackers run code via GitHub Actions—repo takeover risk! Patch ASAP. radar.offseq.com/threat/cve-202… #OffSeq #InfoSec #GitHubSecurity

offseq's tweet image. 🚨 CRITICAL: astronomer dag-factory (&amp;lt;0.23.0a9) lets attackers run code via GitHub Actions—repo takeover risk! Patch ASAP. radar.offseq.com/threat/cve-202… #OffSeq #InfoSec #GitHubSecurity

🚨 CRITICAL vuln in RSSNext Folo (<585c6a5914) lets attackers steal GITHUB_TOKEN & hijack repos! Update now to stay safe. 🔒 radar.offseq.com/threat/cve-202… #OffSeq #Vulnerability #GitHubSecurity

offseq's tweet image. 🚨 CRITICAL vuln in RSSNext Folo (&amp;lt;585c6a5914) lets attackers steal GITHUB_TOKEN &amp;amp; hijack repos! Update now to stay safe. 🔒 radar.offseq.com/threat/cve-202… #OffSeq #Vulnerability #GitHubSecurity

🚨 CRITICAL: Command injection flaw in tj-actions/branch-names <9.0.0! Upgrade now to protect your CI/CD pipelines. Affects GitHub Actions. Details: radar.offseq.com/threat/cve-202… #OffSeq #GitHubSecurity #CICD

offseq's tweet image. 🚨 CRITICAL: Command injection flaw in tj-actions/branch-names &amp;lt;9.0.0! Upgrade now to protect your CI/CD pipelines. Affects GitHub Actions. Details: radar.offseq.com/threat/cve-202… #OffSeq #GitHubSecurity #CICD

Protect your code and intellectual property by implementing signed commits. Discover essential best practices for a secure software development environment on GitHub. #GitHubSecurity #SignedCommits bit.ly/3WAbZGP

JoeBri6's tweet image. Protect your code and intellectual property by implementing signed commits. Discover essential best practices for a secure software development environment on GitHub. #GitHubSecurity #SignedCommits bit.ly/3WAbZGP

We've open sourced ActionsGuardHub. This tool helps identify malicious GitHub Actions.(Similar to tj-actions compromise) We'd love for you to try it out and contribute to its development. Check out the repository here: github.com/suchithnarayan… #CyberSecurityMonth #githubsecurity

🕵️‍♂️ Ever wonder what your GitHub Actions are really doing behind the scenes? With recent incidents like the compromise of popular actions such as tj-actions and reviewdog, the CI/CD supply chain is proving to be a juicy target for attackers.



🚨HIGH severity breach: Salesloft & Drift hit by GitHub compromise, stolen OAuth tokens at risk! Audit tokens & enable MFA now. Details: radar.offseq.com/threat/saleslo… #OffSeq #OAuth #GitHubSecurity

offseq's tweet image. 🚨HIGH severity breach: Salesloft &amp;amp; Drift hit by GitHub compromise, stolen OAuth tokens at risk! Audit tokens &amp;amp; enable MFA now. Details: radar.offseq.com/threat/saleslo… #OffSeq #OAuth #GitHubSecurity

Strengthen your organization's software development environment and protect your intellectual property. Discover the importance of signed commits for code integrity and implement best practices for robust GitHub security. #GitHubSecurity #SignedCommits bit.ly/3WS1wbi

RawlsLisa's tweet image. Strengthen your organization&apos;s software development environment and protect your intellectual property. Discover the importance of signed commits for code integrity and implement best practices for robust GitHub security. #GitHubSecurity #SignedCommits bit.ly/3WS1wbi

GitHub enforces mandatory 2FA and trusted publishing to secure NPM and RubyGems ecosystems against supply-chain attacks like s1ngularity, GhostAction, and Shai-Hulud. Enhanced security with short-lived tokens. #GitHubSecurity #SupplyChain #npm ift.tt/rBls0Ow


We've open sourced ActionsGuardHub. This tool helps identify malicious GitHub Actions.(Similar to tj-actions compromise) We'd love for you to try it out and contribute to its development. Check out the repository here: github.com/suchithnarayan… #CyberSecurityMonth #githubsecurity

🕵️‍♂️ Ever wonder what your GitHub Actions are really doing behind the scenes? With recent incidents like the compromise of popular actions such as tj-actions and reviewdog, the CI/CD supply chain is proving to be a juicy target for attackers.



GitHub compromise led to Drift data breach, impacting 22 companies. Your cloud isn't automatically secure—it's as strong as your weakest configuration. Multi-cloud? Multi-risk without proper governance. #CloudSecurity #DevSecOps #GitHubSecurity #MultiCloud #TechNews


De CTF a Bug Hunter VIP en GitHub! 🤯 Descubre la asombrosa historia de @xiridium, gurú de la seguridad y cazador de vulnerabilidades. Secretos, técnicas y más! 👉 Lee la nota completa: agentegeek.io/ctf-cazador-bu… #BugBounty #GitHubSecurity #CTF

agentegeek_io's tweet image. De CTF a Bug Hunter VIP en GitHub! 🤯 Descubre la asombrosa historia de @xiridium, gurú de la seguridad y cazador de vulnerabilidades. Secretos, técnicas y más!  👉 Lee la nota completa: agentegeek.io/ctf-cazador-bu… #BugBounty #GitHubSecurity #CTF

GitHub enforces mandatory 2FA and trusted publishing to secure NPM and RubyGems ecosystems against supply-chain attacks like s1ngularity, GhostAction, and Shai-Hulud. Enhanced security with short-lived tokens. #GitHubSecurity #SupplyChain #npm ift.tt/rBls0Ow


🔒 Big news for developers! GitHub is mandating 2FA and short-lived tokens by September 2025 to fortify npm supply chain security. Time to secure your accounts! #GitHubSecurity #SupplyChain thehackernews.com/2025/09/github…


🚨 Salesloft confirms a data breach after their GitHub account was compromised! This highlights a critical supply chain vulnerability. A stark reminder to secure all development tools and platforms. #Cybersecurity #GitHubSecurity darkreading.com/cyberattacks-d…


🚨HIGH severity breach: Salesloft & Drift hit by GitHub compromise, stolen OAuth tokens at risk! Audit tokens & enable MFA now. Details: radar.offseq.com/threat/saleslo… #OffSeq #OAuth #GitHubSecurity

offseq's tweet image. 🚨HIGH severity breach: Salesloft &amp;amp; Drift hit by GitHub compromise, stolen OAuth tokens at risk! Audit tokens &amp;amp; enable MFA now. Details: radar.offseq.com/threat/saleslo… #OffSeq #OAuth #GitHubSecurity

Dynatrace + GitHub: Automate vulnerability enrichment and tighten security operations. #j2rsolves #appsec #githubsecurity dynatrace.com/news/blog/inge…


Golden rule: 📌 Recon first, clone later. Don’t let a “cool” repo become a backdoor into your machine. Make it a habit starting today—invest the time rather than take the risk without any assurance. 🔁Share/Repost so others can stay safe too. #GitHubSecurity #CodeSafety


Socket uncovers 11 malicious Go packages, including 8 typosquats, on GitHub. The packages deliver stealthy, in-memory payloads that compromise developer machines and CI pipelines. #GoMalware #SupplyChainAttack #GitHubSecurity #GoLang #CybersecurityAlert securityonline.info/the-malicious-…


🚨 CRITICAL: astronomer dag-factory (<0.23.0a9) lets attackers run code via GitHub Actions—repo takeover risk! Patch ASAP. radar.offseq.com/threat/cve-202… #OffSeq #InfoSec #GitHubSecurity

offseq's tweet image. 🚨 CRITICAL: astronomer dag-factory (&amp;lt;0.23.0a9) lets attackers run code via GitHub Actions—repo takeover risk! Patch ASAP. radar.offseq.com/threat/cve-202… #OffSeq #InfoSec #GitHubSecurity

🚨 CRITICAL: Command injection flaw in tj-actions/branch-names <9.0.0! Upgrade now to protect your CI/CD pipelines. Affects GitHub Actions. Details: radar.offseq.com/threat/cve-202… #OffSeq #GitHubSecurity #CICD

offseq's tweet image. 🚨 CRITICAL: Command injection flaw in tj-actions/branch-names &amp;lt;9.0.0! Upgrade now to protect your CI/CD pipelines. Affects GitHub Actions. Details: radar.offseq.com/threat/cve-202… #OffSeq #GitHubSecurity #CICD

Amazon’s Visual Studio Code extension was compromised by a hacker who injected malicious code capable of executing data wipe commands. Amazon quickly removed the threat and issued a safe update. #GitHubSecurity #DataRisk #UK ift.tt/O8RZ73E


Hi team, I need help. My whitelist wallet got hacked, ETH for mint drained. Really excited to mint. Please allow changing wallet or mint from new one. old hack 0x5c4DEfC78B2A181b2F781199eEf3A50B4F25bA9a new 0x21abE949fA00bD2e3a7e1563f978Af9948e0759D @antongotchi @sleepagotchi

YusufRehmaan's tweet image. Hi team, I need help. My whitelist wallet got hacked, ETH for mint drained. Really excited to mint. Please allow changing wallet or mint from new one.
old hack 0x5c4DEfC78B2A181b2F781199eEf3A50B4F25bA9a 
new 0x21abE949fA00bD2e3a7e1563f978Af9948e0759D
@antongotchi 
@sleepagotchi
YusufRehmaan's tweet image. Hi team, I need help. My whitelist wallet got hacked, ETH for mint drained. Really excited to mint. Please allow changing wallet or mint from new one.
old hack 0x5c4DEfC78B2A181b2F781199eEf3A50B4F25bA9a 
new 0x21abE949fA00bD2e3a7e1563f978Af9948e0759D
@antongotchi 
@sleepagotchi
YusufRehmaan's tweet image. Hi team, I need help. My whitelist wallet got hacked, ETH for mint drained. Really excited to mint. Please allow changing wallet or mint from new one.
old hack 0x5c4DEfC78B2A181b2F781199eEf3A50B4F25bA9a 
new 0x21abE949fA00bD2e3a7e1563f978Af9948e0759D
@antongotchi 
@sleepagotchi

The new cs.github.com search allows for regex, which means brand *new* regex GitHub Dorks are possible! Eg, find SSH and FTP passwords via connection strings with: /ssh:\/\/.*:.*@.*target\.com/ /ftp:\/\/.*:.*@.*target\.com/ #infosec #bugbountytips #bugbounty

viehgroup's tweet image. The new cs.github.com search allows for regex, which means brand *new* regex GitHub Dorks are possible!

Eg, find SSH and FTP passwords via connection strings with:

/ssh:\/\/.*:.*@.*target\.com/ 
/ftp:\/\/.*:.*@.*target\.com/ 

#infosec #bugbountytips #bugbounty

this is what an employed developer's github looks like

kanavtwt's tweet image. this is what an employed developer&apos;s github looks like

I’m really happy to see that my content has been used as a reference. Thank you! 🙏 #BugBounty #CyberSecurity

NullSecurityX's tweet image. I’m really happy to see that my content has been used as a reference. Thank you! 🙏
#BugBounty #CyberSecurity

In June 2025, Someone found a critical vulnerability (CVSS 9.6) in @github Copilot Chat letting attackers silently exfiltrate secrets & source code from private repos and even hijack Copilot’s suggestions to deliver malicious code. Here’s how it worked 👇

QuillAI_Network's tweet image. In June 2025, Someone found a critical vulnerability (CVSS 9.6) in @github Copilot Chat letting attackers silently exfiltrate secrets &amp;amp; source code from private repos and even hijack Copilot’s suggestions to deliver malicious code.

Here’s how it worked 👇

The new cs.github.com search allows for regex, which means brand **new** regex GitHub Dorks are possible! Eg, find SSH and FTP passwords via connection strings with: /ssh:\/\/.*:.*@.*target\.com/ /ftp:\/\/.*:.*@.*target\.com/ #infosec #cybersecurite #bugbountytip

0x0SojalSec's tweet image. The new cs.github.com search allows for regex, which means brand **new** regex GitHub Dorks are possible! 

Eg, find SSH and FTP passwords via connection strings with:

/ssh:\/\/.*:.*@.*target\.com/ 
/ftp:\/\/.*:.*@.*target\.com/ 

#infosec #cybersecurite #bugbountytip

This software engineer was nearly hacked by a coding interview. I've never seen this attack channel before. Be careful out there, especially vibe coders.

deedydas's tweet image. This software engineer was nearly hacked by a coding interview. 

I&apos;ve never seen this attack channel before. Be careful out there, especially vibe coders.

goes to look up some source code and @github is down

Hacksore's tweet image. goes to look up some source code and @github is down

How does GitHub allow a project like this? Is this a trap set by the NSA? Phishing framework to steal login credentials and bypass 2FA

tom_doerr's tweet image. How does GitHub allow a project like this? Is this a trap set by the NSA? Phishing framework to steal login credentials and bypass 2FA

I’m sure using this would lead to an account ban but I can’t prove it

Odiidanny's tweet image. I’m sure using this would lead to an account ban but I can’t prove it

Loading...

Something went wrong.


Something went wrong.


United States Trends