News

Hackers used the secrets stolen in the recent Nx supply chain attack to publish over 6,700 private repositories publicly.
An Argo CD vulnerability allows API tokens with even low project-level get permissions to access API endpoints and retrieve ...
A scan of billions of files from 13 percent of all GitHub public repositories over a period of six months has revealed that over 100,000 repos have leaked API tokens and cryptographic keys, with ...
Attackers abused GitHub Actions workflows to siphon off thousands of credentials from hundreds of npm and PyPI repositories.
On August 26, 2025, Nx, the popular build platform with millions of weekly downloads, was compromised with ...
On September 5, 2025, GitGuardian discovered GhostAction, a massive supply chain attack affecting 327 GitHub users across 817 ...
GitHub is now automatically blocking the leak of sensitive information like API keys and access tokens for all public code repositories.