logoalt Hacker News

GitHub is investigating unauthorized access to their internal repositories

155 pointsby splenditertoday at 12:01 AM35 commentsview on HN

Comments

vldszntoday at 12:56 AM

GitHub: "We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity."

show 1 reply
keyletoday at 1:44 AM

This is bad. If they came out announcing this, without a long winded explanation and further details, it's because they're staring at a bottomless pit and they haven't put the lid on it yet.

For a Fortune 100, to go out of your way to spook investors is the least desirable approach.

show 1 reply
vldszntoday at 12:34 AM

- Use Static analysis for GHA to catch security issues: https://github.com/zizmorcore/zizmor

- set locally: pnpm config set minimum-release-age 4320 # 3 days in minutes https://pnpm.io/supply-chain-security for other package managers check: https://gist.github.com/mcollina/b294a6c39ee700d24073c0e5a4e...

- add Socket Free Firewall when installing npm packages on CI https://docs.socket.dev/docs/socket-firewall-free#github-act...

show 3 replies
surrTurrtoday at 2:19 AM

"Someone broke into our house and we have no clue if they're still hiding under the bed or in the drawer. TV is gone."

killingtime74today at 1:52 AM

Time to switch to Gitlab, Bitbucket or self-hosted

MallocVoidstartoday at 1:50 AM

https://pbs.twimg.com/media/HItbXhvW4AAMD8W?format=jpg&name=...

All of their repos have been copied and are up for sale. Attackers are TeamPCP, the creators of the Shai-Hulud malware.

show 1 reply
waynesonfiretoday at 1:01 AM

Are they required to announce that they're being hacked in real time?

show 1 reply
mstanktoday at 12:27 AM

Is it just me or is this happening way more frequently in the last 4 or 5 months? Coincidently around the same time the models got a lot more capable?

show 4 replies
syngrog66today at 12:47 AM

between all the Linux LPEs and Claude's known security flaws, alone, I'd be shocked if Github and Microsoft hadnt gotten hacked by now. reasonable bet we mainly hear it when big shops get bit

show 1 reply
uzyntoday at 1:07 AM

[dead]

jonnyasmartoday at 12:14 AM

[flagged]

show 1 reply
kiernanmcgowantoday at 12:38 AM

Mythos has broken containment

tiffanyhtoday at 2:03 AM

Is Twitter/X the right channel to announce a security event like this?

I ask because I don’t see anything posted on their official blog or status page.

https://github.blog/

https://www.githubstatus.com/

show 1 reply