GitHub - Tagged - Security Boulevard The Home of the Security Bloggers Network Fri, 21 Jul 2023 19:51:33 +0000 en-US hourly 1 https://wordpress.org/?v=6.2.2 https://securityboulevard.com/wp-content/uploads/2021/10/android-chrome-256x256-1-32x32.png GitHub - Tagged - Security Boulevard 32 32 133346385 GitHub Developers Targeted by North Korea’s Lazarus Group https://securityboulevard.com/2023/07/github-developers-targeted-by-north-koreas-lazarus-group/ Fri, 21 Jul 2023 19:51:33 +0000 https://securityboulevard.com/?p=1982351 GitHub satellite cyberattack Strontium cyberwarfare counter-drone The Legality of Waging War in Cyberspace

The Lazarus Group is behind a social engineering campaign that uses repository invitations and malicious npm packages to target developers on GitHub.

The post GitHub Developers Targeted by North Korea’s Lazarus Group appeared first on Security Boulevard.

]]>
1982351
After Brief Exposure in Public Repo, GitHub Rotated Private SSH Key https://securityboulevard.com/2023/04/after-brief-exposure-in-public-repo-github-rotated-private-ssh-key/ Mon, 03 Apr 2023 11:26:56 +0000 https://securityboulevard.com/?p=1970507 RagnarLocker PKIaaS certificate key management PKI SSH key

In an attempt to get ahead of fallout from the exposure of its private SSH key in a public repository, the software development platform GitHub proactively rotated its host key last week. “Out of an abundance of caution, we replaced our RSA SSH host key used to secure Git operations for GitHub.com,” GitHub CSO and SVP..

The post After Brief Exposure in Public Repo, GitHub Rotated Private SSH Key appeared first on Security Boulevard.

]]>
1970507
Twitter Presses GitHub to Turn Over User Who Leaked Source Code https://securityboulevard.com/2023/03/twitter-presses-github-to-turn-over-user-who-leaked-source-code/ Fri, 31 Mar 2023 12:38:07 +0000 https://securityboulevard.com/?p=1970373 Twitter attack Nestlé hacker ransomware breach malware

When Twitter joined the ranks of tech companies whose source code leaked online, it was met with little surprise and a whole lot of unease over what the leak might mean for the platform’s security. “Unlike other recent source code leaks, it is concerning that Twitter has not released a statement to reiterate that it..

The post Twitter Presses GitHub to Turn Over User Who Leaked Source Code appeared first on Security Boulevard.

]]>
1970373
Supply Chain Dependency: What Your GitHub Connections May Trigger https://securityboulevard.com/2023/02/supply-chain-dependency-what-your-github-connections-may-trigger/ Mon, 27 Feb 2023 14:00:20 +0000 https://securityboulevard.com/?p=1965381 GitHub connections digital pipeline GitHub ICS Risk

The writing is on the walls, and it’s hard to avoid after the significant spike in attacks against GitHub repositories. The recent CircleCI breach, in which customers’ secrets and encryption keys were stolen, make it very clear that attackers already understand and leverage this vector. Now more than ever, is the time for companies to..

The post Supply Chain Dependency: What Your GitHub Connections May Trigger appeared first on Security Boulevard.

]]>
1965381
Legitify adds support for GitLab and GitHub Enterprise Server https://securityboulevard.com/2023/01/legitify-adds-support-for-gitlab-and-github-enterprise-server/ Wed, 25 Jan 2023 20:09:07 +0000 https://www.legitsecurity.com/blog/legitify-adds-support-for-gitlab-and-github-enterprise-server Legitify adds support for GitLab and GitHub Enterprise Server

We encounter security incidents on a weekly basis with prospective customers that involve pipeline manipulation, code theft, and sensitive data exposure - many of which result from bad source code management (SCM) system configurations. Legitify, the open-source security tool we recently announced, is rapidly gaining popularity because it helps users analyze and remediate the security configuration of their SCM resources. 

The post Legitify adds support for GitLab and GitHub Enterprise Server appeared first on Security Boulevard.

]]>
1961798
LastPass Password Vaults Stolen, Pig Butchering Scams, Okta Source Code Theft https://securityboulevard.com/2023/01/lastpass-password-vaults-stolen-pig-butchering-scams-okta-source-code-theft/ Mon, 09 Jan 2023 05:00:41 +0000 https://sharedsecurity.net/?p=101284 Things get worse for LastPass as a security breach in November resulted in the theft of customer data, including encrypted password vaults and unencrypted web addresses. Pig butchering scams, a variation of business email compromise and romance scams, are on the rise. How do they work and what do you need to know to protect […]

The post LastPass Password Vaults Stolen, Pig Butchering Scams, Okta Source Code Theft appeared first on The Shared Security Show.

The post LastPass Password Vaults Stolen, Pig Butchering Scams, Okta Source Code Theft appeared first on Security Boulevard.

]]>
1951684
Tips & Best Practices for Configuring Squid with NTLM Authentication https://securityboulevard.com/2022/12/tips-best-practices-for-configuring-squid-with-ntlm-authentication/ Tue, 20 Dec 2022 14:00:02 +0000 https://www.anitian.com/?p=243190 If you’ve ever worked in environments requiring a proxy, reverse proxy, or caching system, you’ve likely heard of Squid proxy. Squid is one of the leading open-source proxy tools with an extensive community and available plugin library. As is the case with many large, open source projects, there are many different ways to accomplish a […]

The post Tips & Best Practices for Configuring Squid with NTLM Authentication appeared first on Anitian.

The post Tips & Best Practices for Configuring Squid with NTLM Authentication appeared first on Security Boulevard.

]]>
1950133
GitHub Secret Scanning is now Free (as in Beer) https://securityboulevard.com/2022/12/github-secret-scanning-free-richixbw/ Mon, 19 Dec 2022 17:24:31 +0000 https://securityboulevard.com/?p=1949989

Microsoft’s GitHub source control service will help stop devs accidentally embedding secrets in public code repositories. It’s a big problem.

The post GitHub Secret Scanning is now Free (as in Beer) appeared first on Security Boulevard.

]]>
1949989
GitHub Flaw Underscores Risks of Open Source, RepoJacking https://securityboulevard.com/2022/11/github-flaw-underscores-risks-of-open-source-repojacking/ Wed, 02 Nov 2022 12:00:43 +0000 https://securityboulevard.com/?p=1943409 GitHub connections digital pipeline GitHub ICS Risk

A GitHub vulnerability was recently discovered that lets attackers seize control of a GitHub repository and infect all the applications and code that depend on it with malicious code. This vulnerability is a wake-up call for those who rely on open source packages, which are now at risk. “This is not much different than the..

The post GitHub Flaw Underscores Risks of Open Source, RepoJacking appeared first on Security Boulevard.

]]>
1943409
Detect vulnerable libraries within GitHub environments for free with CodeSec | Contrast Security https://securityboulevard.com/2022/10/detect-vulnerable-libraries-within-github-environments-for-free-with-codesec-contrast-security/ Mon, 17 Oct 2022 15:49:03 +0000 https://www.contrastsecurity.com/security-influencers/detect-vulnerable-libraries-within-your-github-environments-for-free Detect vulnerable libraries within GitHub environments for free with CodeSec | Contrast Security

Combine the power of GitHub Actions for automated Continuous Integration/Continuous Deployment (CI/CD) pipelines with Contrast Security’s powerful free developer tool, CodeSec, to identify vulnerable dependencies in your Java, .NET, NodeJS, Ruby, Python, Go or PHP projects.

The post Detect vulnerable libraries within GitHub environments for free with CodeSec | Contrast Security appeared first on Security Boulevard.

]]>
1941937