Binance Square
#github

github

70,380 ogledov
127 razprav
TinTucBitcoin
·
--
·
--
Bikovski
⚠️ALERTA: HACKERS SE ATRIBUYEN UNA FILTRACIÓN MASIVA DE CÓDIGO FUENTE INTERNO DE GITHUB El grupo de ciberdelincuentes TeamPCP se ha atribuido la responsabilidad de la filtración de los sistemas internos de GitHub y el robo de datos vinculados a aproximadamente 4000 repositorios privados que supuestamente contienen código fuente propietario de la plataforma y archivos internos de la organización. Según se informa, el grupo está intentando vender el conjunto de datos en foros clandestinos de ciberdelincuencia por más de 50 000 dólares. Si bien #GitHub confirmó que está investigando el acceso no autorizado a los repositorios internos, se insta a los desarrolladores a revisar cuidadosamente y cambiar las claves API si están presentes en los repositorios. $BTC $WLD $ETH
⚠️ALERTA: HACKERS SE ATRIBUYEN UNA FILTRACIÓN MASIVA DE CÓDIGO FUENTE INTERNO DE GITHUB

El grupo de ciberdelincuentes TeamPCP se ha atribuido la responsabilidad de la filtración de los sistemas internos de GitHub y el robo de datos vinculados a aproximadamente 4000 repositorios privados que supuestamente contienen código fuente propietario de la plataforma y archivos internos de la organización.

Según se informa, el grupo está intentando vender el conjunto de datos en foros clandestinos de ciberdelincuencia por más de 50 000 dólares.

Si bien #GitHub confirmó que está investigando el acceso no autorizado a los repositorios internos, se insta a los desarrolladores a revisar cuidadosamente y cambiar las claves API si están presentes en los repositorios.
$BTC $WLD $ETH
emilia5202:
Hola si pudieran ayudarme🫶🏻 reclamando mi sobre rojo acá les dejo el código: BP7DSCPMMG 👈🏻
GitHub Internal Breach Alert 🚨: TeamPCP claims exfiltration of ~4,000 private repos via a malicious VS Code extension on an employee device. • No customer data leaked (yet). • Supply chain attacks are the new norm. • Action: Audit your extensions, rotate secrets, and enforce endpoint security. Don't be the weakest link. 🛡️ #GitHub #CyberSecurity #TeamPCP #DevOps #SecurityAlert
GitHub Internal Breach Alert 🚨: TeamPCP claims exfiltration of ~4,000 private repos via a malicious VS Code extension on an employee device.
• No customer data leaked (yet).
• Supply chain attacks are the new norm.
• Action: Audit your extensions, rotate secrets, and enforce endpoint security.
Don't be the weakest link. 🛡️
#GitHub #CyberSecurity #TeamPCP #DevOps #SecurityAlert
Ms Puiyi:
Classic supply chain attack vector. VS Code extension risk is real.
🚨 Developers are freaking out after reports of a massive GitHub breach started spreading online. A hacker group called “TeamPCP” claims it broke into GitHub’s internal systems and accessed data connected to nearly 4,000 private repositories. The leaked information allegedly includes internal company files and even parts of GitHub’s proprietary source code. 😳💻 And it gets worse. The group is reportedly trying to sell the stolen data on underground cybercrime forums for more than $50,000. That alone has sparked major concern across the tech world. 🔥 GitHub says it’s investigating the unauthorized access, but developers aren’t waiting around. Many are already rushing to change API keys, secure repositories, and remove sensitive credentials before things spiral further. ⚠️🔐 If these claims are confirmed, this could turn into one of the biggest security scares the developer community has seen in years. One exposed token or private key can open the door to much larger attacks, which is why cybersecurity experts are telling users to act fast and stay alert. #GitHub #CyberSecurity #DataBreach $GTC {future}(GTCUSDT) $PHB {spot}(PHBUSDT) $EDEN {future}(EDENUSDT)
🚨 Developers are freaking out after reports of a massive GitHub breach started spreading online.

A hacker group called “TeamPCP” claims it broke into GitHub’s internal systems and accessed data connected to nearly 4,000 private repositories. The leaked information allegedly includes internal company files and even parts of GitHub’s proprietary source code. 😳💻

And it gets worse.

The group is reportedly trying to sell the stolen data on underground cybercrime forums for more than $50,000. That alone has sparked major concern across the tech world. 🔥

GitHub says it’s investigating the unauthorized access, but developers aren’t waiting around. Many are already rushing to change API keys, secure repositories, and remove sensitive credentials before things spiral further. ⚠️🔐

If these claims are confirmed, this could turn into one of the biggest security scares the developer community has seen in years. One exposed token or private key can open the door to much larger attacks, which is why cybersecurity experts are telling users to act fast and stay alert.

#GitHub #CyberSecurity #DataBreach

$GTC
$PHB
$EDEN
GITHUB BREACH RATTLES DEV SECURITY FOR $BTC 🛡️ GitHub disclosed unauthorized access to internal repositories following a malicious VS Code plugin attack on an employee device. The company says the incident appears limited to internal repository theft, with the attacker’s claim of roughly 3,800 repositories broadly aligned with its investigation. For crypto markets, the key issue is infrastructure trust. GitHub has removed the plugin, isolated endpoints, rotated critical keys, and continues log analysis. Traders should monitor whether any downstream developer, exchange, or protocol exposure emerges before assuming broader market impact. Not financial advice. Manage your risk. #CryptoSecurity #GitHub #BTC #CyberSecurit #BinanceSquar 🛡️ {future}(BTCUSDT)
GITHUB BREACH RATTLES DEV SECURITY FOR $BTC 🛡️

GitHub disclosed unauthorized access to internal repositories following a malicious VS Code plugin attack on an employee device. The company says the incident appears limited to internal repository theft, with the attacker’s claim of roughly 3,800 repositories broadly aligned with its investigation.

For crypto markets, the key issue is infrastructure trust. GitHub has removed the plugin, isolated endpoints, rotated critical keys, and continues log analysis. Traders should monitor whether any downstream developer, exchange, or protocol exposure emerges before assuming broader market impact.

Not financial advice. Manage your risk.

#CryptoSecurity #GitHub #BTC #CyberSecurit #BinanceSquar

🛡️
🚨 GITHUB MAY HAVE JUST SUFFERED A MAJOR INTERNAL SOURCE CODE BREACH Hackers from the group “TeamPCP” claim they infiltrated GitHub’s internal systems and stole data linked to nearly 4,000 private repositories. The alleged haul includes proprietary platform source code, internal organization files, and potentially sensitive developer infrastructure. Now the dataset is reportedly being offered for sale on underground cybercrime forums for over $50,000. GitHub says it is actively investigating unauthorized access to internal repositories. But the bigger concern is what could already be exposed. If API keys, secrets, deployment tokens, or credentials were stored inside affected repos, this could quickly escalate into a much wider supply chain security event. Developers and companies are now being urged to rotate API keys, audit repository access, and review authentication logs immediately. One compromised repository can become an entry point into cloud systems, wallets, databases, exchanges, or enterprise infrastructure. This is why cybersecurity experts constantly warn: Private repositories are not the same thing as secure repositories. If confirmed, this could become one of the most important developer security incidents of the year. #GitHub #Cybersecurity #Hackers #DataBreach #BreakingNews
🚨 GITHUB MAY HAVE JUST SUFFERED A MAJOR INTERNAL SOURCE CODE BREACH

Hackers from the group “TeamPCP” claim they infiltrated GitHub’s internal systems and stole data linked to nearly 4,000 private repositories.

The alleged haul includes proprietary platform source code, internal organization files, and potentially sensitive developer infrastructure.

Now the dataset is reportedly being offered for sale on underground cybercrime forums for over $50,000.

GitHub says it is actively investigating unauthorized access to internal repositories.

But the bigger concern is what could already be exposed.

If API keys, secrets, deployment tokens, or credentials were stored inside affected repos, this could quickly escalate into a much wider supply chain security event.

Developers and companies are now being urged to rotate API keys, audit repository access, and review authentication logs immediately.

One compromised repository can become an entry point into cloud systems, wallets, databases, exchanges, or enterprise infrastructure.

This is why cybersecurity experts constantly warn:

Private repositories are not the same thing as secure repositories.

If confirmed, this could become one of the most important developer security incidents of the year.

#GitHub #Cybersecurity #Hackers #DataBreach #BreakingNews
$BNB SECURITY ALERT AFTER GITHUB ACCESS INCIDENT ⚠️ CZ reminded developers to immediately review and replace any API key found in code, even inside private repositories, after GitHub disclosed unauthorized access to internal code repositories. GitHub said there is currently no evidence that customer repositories or external enterprise data were compromised, while monitoring continues. For crypto teams and active traders, exposed API keys remain a material operational risk, especially when connected to exchange accounts, bots, or automated execution systems. The prudent response is key rotation, permission review, withdrawal restrictions, and tighter repository hygiene. Not financial advice. Manage your risk. #CryptoSecurity #BNB #GitHub #BinanceSquare #RiskManagement ✅ {future}(BNBUSDT)
$BNB SECURITY ALERT AFTER GITHUB ACCESS INCIDENT ⚠️

CZ reminded developers to immediately review and replace any API key found in code, even inside private repositories, after GitHub disclosed unauthorized access to internal code repositories. GitHub said there is currently no evidence that customer repositories or external enterprise data were compromised, while monitoring continues.

For crypto teams and active traders, exposed API keys remain a material operational risk, especially when connected to exchange accounts, bots, or automated execution systems. The prudent response is key rotation, permission review, withdrawal restrictions, and tighter repository hygiene.

Not financial advice. Manage your risk.

#CryptoSecurity #BNB #GitHub #BinanceSquare #RiskManagement

$BNB SECURITY ALERT JUST HIT THE DEV STACK 🚨 CZ flagged it hard: if an API key is sitting in code, even inside a private repo, review it and replace it immediately. GitHub is investigating unauthorized access to internal code repositories, while stating there is no current evidence that customer-stored enterprise, organization, or external repo data was compromised. This is a clean risk-control warning for builders, funds, bots, and trading desks. API exposure can turn into instant damage. Rotate keys. Lock permissions. Monitor activity. Security is alpha when markets move fast. Not financial advice. Manage your risk. #Binance #CryptoSecurity #BNB #GitHub #CryptoNews ⚡ {future}(BNBUSDT)
$BNB SECURITY ALERT JUST HIT THE DEV STACK 🚨

CZ flagged it hard: if an API key is sitting in code, even inside a private repo, review it and replace it immediately. GitHub is investigating unauthorized access to internal code repositories, while stating there is no current evidence that customer-stored enterprise, organization, or external repo data was compromised.

This is a clean risk-control warning for builders, funds, bots, and trading desks.

API exposure can turn into instant damage.
Rotate keys. Lock permissions. Monitor activity.
Security is alpha when markets move fast.

Not financial advice. Manage your risk.

#Binance #CryptoSecurity #BNB #GitHub #CryptoNews

اختراق مستودعات Grafana: الابتزاز يفشل والأمان ينتصر 🛡️ ​حتى العمالقة يتعرضون للاختبار، لكن القوة الحقيقية تظهر في طريقة المواجهة. ​مؤخراً، واجهت منصة Grafana الشهيرة لتحليل البيانات حادثة أمنية بعد وصول غير مصرح به إلى بيئتها على GitHub. المهاجم نجح في الحصول على رمز وصول (Token) مكنه من تحميل بعض الأكواد البرمجية الخاصة بالشركة. ​لكن، إليك الجانب المضيء والأهم في هذه القصة: ​بياناتك في أمان: أكدت التحقيقات بشكل قاطع عدم المساس بأي من بيانات العملاء أو معلوماتهم الشخصية. ​استمرارية العمل: لم تتأثر الأنظمة التشغيلية أو الخدمات بأي شكل من الأشكال. ​لا خضوع للابتزاز: حاول المهاجم ابتزاز الشركة ودفع فدية مقابل عدم نشر الكود، وكان رد Grafana حاسماً: "لن ندفع". ​الشركة واجهت الموقف بشفافية، وبدأت فوراً تحليلاً جنائياً رقمياً لمعرفة مصدر التسريب، مع تعزيز تدابيرها الأمنية لضمان عدم تكرار الأمر. ​الدرس المستفاد هنا؟ الثقة لا تبنى بغياب الأخطاء، بل بكيفية التعامل معها وحماية المستخدمين كأولوية قصوى. ​💬 شاركنا رأيك في التعليقات: كيف ترى قرار Grafana برفض دفع الفدية؟ هل تعتقد أن الشفافية في الحوادث الأمنية تعزز ثقة المستخدمين أم تهزها؟ ​#Grafana #CyberSecurity #Github #CryptoNews #BinanceSquare
اختراق مستودعات Grafana: الابتزاز يفشل والأمان ينتصر 🛡️

​حتى العمالقة يتعرضون للاختبار، لكن القوة الحقيقية تظهر في طريقة المواجهة.

​مؤخراً، واجهت منصة Grafana الشهيرة لتحليل البيانات حادثة أمنية بعد وصول غير مصرح به إلى بيئتها على GitHub. المهاجم نجح في الحصول على رمز وصول (Token) مكنه من تحميل بعض الأكواد البرمجية الخاصة بالشركة.

​لكن، إليك الجانب المضيء والأهم في هذه القصة:

​بياناتك في أمان: أكدت التحقيقات بشكل قاطع عدم المساس بأي من بيانات العملاء أو معلوماتهم الشخصية.

​استمرارية العمل: لم تتأثر الأنظمة التشغيلية أو الخدمات بأي شكل من الأشكال.

​لا خضوع للابتزاز: حاول المهاجم ابتزاز الشركة ودفع فدية مقابل عدم نشر الكود، وكان رد Grafana حاسماً: "لن ندفع".

​الشركة واجهت الموقف بشفافية، وبدأت فوراً تحليلاً جنائياً رقمياً لمعرفة مصدر التسريب، مع تعزيز تدابيرها الأمنية لضمان عدم تكرار الأمر.

​الدرس المستفاد هنا؟ الثقة لا تبنى بغياب الأخطاء، بل بكيفية التعامل معها وحماية المستخدمين كأولوية قصوى.

​💬 شاركنا رأيك في التعليقات: كيف ترى قرار Grafana برفض دفع الفدية؟ هل تعتقد أن الشفافية في الحوادث الأمنية تعزز ثقة المستخدمين أم تهزها؟

#Grafana #CyberSecurity #Github #CryptoNews #BinanceSquare
·
--
@Torkelrogstad: Brand new scam technique just dropped: #github bots trying to phish you into downloading #Malware . Within a minute of creating an issue mentioning the words "seed derivation" and "xpriv", a shady-looking link was posted by a bot. Stay vigilant, folks! #phishing #Hacked
@Torkelrogstad: Brand new scam technique just dropped: #github bots trying to phish you into downloading #Malware .

Within a minute of creating an issue mentioning the words "seed derivation" and "xpriv", a shady-looking link was posted by a bot.

Stay vigilant, folks! #phishing #Hacked
·
--
(#Cryptodiffer ) Top-15 Projects by average daily development activity growth on #github in the last 30 days$PHA $FIO $POLYX $WLD $SAITO $RPL $JUP $XYO $MINA $BZZ $KDA $PNK $GNO $ZIL #1INCH
(#Cryptodiffer )
Top-15 Projects by average daily development activity growth on #github in the last 30 days$PHA $FIO $POLYX $WLD $SAITO $RPL $JUP $XYO $MINA $BZZ $KDA $PNK $GNO $ZIL #1INCH
How Hackers Use GitHub to Stay Under the RadarIn the world of cybersecurity, attackers are always evolving, finding new ways to hide in plain sight, and one of the latest examples shows just how creative they’ve become. The case of the Astaroth banking trojan demonstrates how hackers are now using legitimate platforms like GitHub to stay invisible to security experts while continuing to steal sensitive information It all begins with a simple phishing email that looks completely normal, often disguised as an official message asking you to download an important document. The attached file, usually with a .lnk extension that appears harmless, is actually a trap. Once opened, it silently installs malware onto your device and begins its work in the background. What follows is a stealthy operation where the trojan quietly records your keystrokes, capturing logins, passwords, and other personal data connected to your bank accounts and crypto wallets. All that stolen information is then sent back to the attackers who control the malware’s network But the truly fascinating part is how Astaroth manages to remain undetected for so long. Most trojans rely on a central command server that coordinates all infected machines. Once authorities discover and take down that server, the entire operation falls apart. Astaroth, however, doesn’t play by those rules. Instead, it uses GitHub — the same platform developers use to host and share open-source code — as part of its communication system. The malware doesn’t store any dangerous files there but hides a small configuration file in a GitHub repository. That file contains new instructions, such as where to connect next if the main server goes offline. In essence, GitHub acts as a message board for the trojan, telling it where to find the next command center without ever raising suspicion According to cybersecurity experts at McAfee, this trick makes Astaroth remarkably resilient. Even if one part of its infrastructure is destroyed, it can quickly recover and continue its operations using legitimate channels that no one expects to be part of a cyberattack. To make things even more sophisticated, the trojan is programmed to avoid drawing attention from analysts in certain countries. If it detects that it’s running on a system based in the United States or another English-speaking region, it deletes itself immediately, leaving no trace behind. Its main focus has been users in South America, particularly in Brazil, Argentina, and Chile, where it has caused significant damage So what can regular users do in the face of such clever tactics? The answers may sound familiar, but they are more important than ever. Never open attachments or click on links from unknown senders, no matter how legitimate they appear. Keep your antivirus software updated and make sure it’s actively monitoring your system. Most importantly, use two-factor authentication on all your critical accounts, especially for online banking and crypto exchanges. Even if your password is stolen, the attacker will need an additional code to access your funds The Astaroth case is a powerful reminder that even trusted and widely used platforms like GitHub can be misused for malicious purposes. It challenges the very idea of online safety, showing that in today’s digital landscape, the line between good and bad tools depends entirely on how they’re used. Perhaps there is no truly safe place on the internet anymore only safer habits and smarter vigilance that help us stay one step ahead #GitHub #Cybersecurity #CryptoNews #McAfee #OnlineSafety

How Hackers Use GitHub to Stay Under the Radar

In the world of cybersecurity, attackers are always evolving, finding new ways to hide in plain sight, and one of the latest examples shows just how creative they’ve become. The case of the Astaroth banking trojan demonstrates how hackers are now using legitimate platforms like GitHub to stay invisible to security experts while continuing to steal sensitive information
It all begins with a simple phishing email that looks completely normal, often disguised as an official message asking you to download an important document. The attached file, usually with a .lnk extension that appears harmless, is actually a trap. Once opened, it silently installs malware onto your device and begins its work in the background. What follows is a stealthy operation where the trojan quietly records your keystrokes, capturing logins, passwords, and other personal data connected to your bank accounts and crypto wallets. All that stolen information is then sent back to the attackers who control the malware’s network
But the truly fascinating part is how Astaroth manages to remain undetected for so long. Most trojans rely on a central command server that coordinates all infected machines. Once authorities discover and take down that server, the entire operation falls apart. Astaroth, however, doesn’t play by those rules. Instead, it uses GitHub — the same platform developers use to host and share open-source code — as part of its communication system. The malware doesn’t store any dangerous files there but hides a small configuration file in a GitHub repository. That file contains new instructions, such as where to connect next if the main server goes offline. In essence, GitHub acts as a message board for the trojan, telling it where to find the next command center without ever raising suspicion
According to cybersecurity experts at McAfee, this trick makes Astaroth remarkably resilient. Even if one part of its infrastructure is destroyed, it can quickly recover and continue its operations using legitimate channels that no one expects to be part of a cyberattack. To make things even more sophisticated, the trojan is programmed to avoid drawing attention from analysts in certain countries. If it detects that it’s running on a system based in the United States or another English-speaking region, it deletes itself immediately, leaving no trace behind. Its main focus has been users in South America, particularly in Brazil, Argentina, and Chile, where it has caused significant damage
So what can regular users do in the face of such clever tactics? The answers may sound familiar, but they are more important than ever. Never open attachments or click on links from unknown senders, no matter how legitimate they appear. Keep your antivirus software updated and make sure it’s actively monitoring your system. Most importantly, use two-factor authentication on all your critical accounts, especially for online banking and crypto exchanges. Even if your password is stolen, the attacker will need an additional code to access your funds
The Astaroth case is a powerful reminder that even trusted and widely used platforms like GitHub can be misused for malicious purposes. It challenges the very idea of online safety, showing that in today’s digital landscape, the line between good and bad tools depends entirely on how they’re used. Perhaps there is no truly safe place on the internet anymore only safer habits and smarter vigilance that help us stay one step ahead
#GitHub #Cybersecurity #CryptoNews #McAfee #OnlineSafety
#Microsoft 's Independent Strategy in the AI Race: On the Path to a $5 Trillion Valuation Microsoft is advancing its #Aİ capabilities beyond its OpenAI partnership, leading analysts to hope its market value could reach $5 trillion by 2026. The company's current value is $3.59 trillion. Microsoft's AI Empire: With and Without OpenAI Microsoft has invested approximately $13 billion in OpenAI to date, securing a 27% ownership stake. However, the majority of Microsoft's AI revenue (75%) comes from its own Azure AI services, not from reselling OpenAI's models (which accounts for only 6%). Microsoft has made a $5 billion investment in Anthropic, which will purchase $30 billion in Azure computing. The company has locked in $250 billion in Azure commitments and intends to spend $80 billion on AI infrastructure by 2025. Integrating AI into Every Product Microsoft has implemented AI across all its major product lines: Copilot has been integrated into Microsoft 365, Windows, and #Github . AI capabilities are now part of the Azure cloud, Office apps, Bing, Edge, and developer tools. According to experts, the company's broad reach (Azure training, GitHub Copilot, Office AI) is its biggest advantage for the next decade. The Next Step: Agentic AI Analysts believe Agentic AI (AI capable of handling multi-step tasks) could be Microsoft's next breakthrough, where it will lead alongside ServiceNow and Salesforce. Risks and Challenges Heavy infrastructure investments by Microsoft could be at risk if AI demand weakens or competing models improve. The company could face challenges if market sentiment is affected by AI delivery outcomes. Microsoft continues to strengthen its independent position in the AI race, where the OpenAI partnership is an important pillar, but only one part of the overall strategy. #USJobsData #TrumpTariffs {future}(BTCUSDT) {future}(SOLUSDT)
#Microsoft 's Independent Strategy in the AI Race: On the Path to a $5 Trillion Valuation
Microsoft is advancing its #Aİ capabilities beyond its OpenAI partnership, leading analysts to hope its market value could reach $5 trillion by 2026. The company's current value is $3.59 trillion.
Microsoft's AI Empire: With and Without OpenAI
Microsoft has invested approximately $13 billion in OpenAI to date, securing a 27% ownership stake.
However, the majority of Microsoft's AI revenue (75%) comes from its own Azure AI services, not from reselling OpenAI's models (which accounts for only 6%).
Microsoft has made a $5 billion investment in Anthropic, which will purchase $30 billion in Azure computing.
The company has locked in $250 billion in Azure commitments and intends to spend $80 billion on AI infrastructure by 2025.
Integrating AI into Every Product
Microsoft has implemented AI across all its major product lines:
Copilot has been integrated into Microsoft 365, Windows, and #Github .
AI capabilities are now part of the Azure cloud, Office apps, Bing, Edge, and developer tools.
According to experts, the company's broad reach (Azure training, GitHub Copilot, Office AI) is its biggest advantage for the next decade.
The Next Step: Agentic AI
Analysts believe Agentic AI (AI capable of handling multi-step tasks) could be Microsoft's next breakthrough, where it will lead alongside ServiceNow and Salesforce.
Risks and Challenges
Heavy infrastructure investments by Microsoft could be at risk if AI demand weakens or competing models improve.
The company could face challenges if market sentiment is affected by AI delivery outcomes.
Microsoft continues to strengthen its independent position in the AI race, where the OpenAI partnership is an important pillar, but only one part of the overall strategy.

#USJobsData #TrumpTariffs
Prijavite se, če želite raziskati več vsebin
Pridružite se globalnim kriptouporabnikom na trgu Binance Square
⚡️ Pridobite najnovejše in koristne informacije o kriptovalutah.
💬 Zaupanje največje borze kriptovalut na svetu.
👍 Odkrijte prave vpoglede potrjenih ustvarjalcev.
E-naslov/telefonska številka