Coincidentally (?) we’ve seen a huge uptick in failed login attempts to our MFA-protected admin accounts on our self-hosted Gitlab CE instance today. They’re coming from thousands of IPs across hundreds of networks (VPS providers and, apparently, residential proxies).
It's probably related to the issue published by aikidolabs where leaked per-user gitlab issued emails were being used as a sort of credential.
There was a relative lull in GitHub bot activity the last few weeks, but they seem to be back today. I assume the promo token flood gates opened for the new models.