https://pbs.twimg.com/media/HItbXhvW4AAMD8W?format=jpg&name=... All of their repos have been copied and are up for sale. Attackers are TeamPCP, the creators of the Shai-Hulud malware.
If that’s true and they do intend on shredding their copy on sale, what stops GitHub from buying it back themselves? (through a proxy, obv)
GitHub is investigating unauthorized access to their internal repositories
51–60 of 359 posts
Re: GitHub is investigating unauthorized access to their internal repositories
#52Re: GitHub is investigating unauthorized access to their internal repositories
#53Is it just me or is this happening way more frequently in the last 4 or 5 months? Coincidently around the same time the models got a lot more capable?
I heard an engineer at Anthropic was submitting 150 PRs per day. That's one PR every 5 to 10 minutes, so you can guess the level of review and quality control involved.
Re: GitHub is investigating unauthorized access to their internal repositories
#54Earlier quoted context omitted.
There is a 100% chance that people are using LLMs to find vulnerabilities and build exploits. If it was possible for something to be a 101% chance, that's what it would be.
Apologies to all - I am British. The phrase "non-zero" does cover every case other than zero, but the intent is that it covers some cases more than others. What I'm trying to say is: yes. My intent was just to push back on this specific (and slightly bizarre to me) instance of kind-of-vagueposting, to my eyes written to imply that it might be some sort of unnoticed conspiracy, detectable only by the most enlightened…
Re: GitHub is investigating unauthorized access to their internal repositories
#55Earlier quoted context omitted.
It’s a very popular messaging platform for tech enthusiasts.
So? Is this where your corporate paying clients should find out about an issue of this severity? Not to mention Twitter is not an open platform anymore! (A) I'm an employee in an organization paying for Github. (B) I don't have a Twitter account. I already have a Github account because of (A). Why should (B) stop/delay me from getting official comms about this?
Re: GitHub is investigating unauthorized access to their internal repositories
#56Earlier quoted context omitted.
So? Is this where your corporate paying clients should find out about an issue of this severity? Not to mention Twitter is not an open platform anymore! (A) I'm an employee in an organization paying for Github. (B) I don't have a Twitter account. I already have a Github account because of (A). Why should (B) stop/delay me from getting official comms about this?
I can't imagine they'd spam every account with an email address, though an email to organization owners would make more sense.
It's not "spam" if it is relevant to me, such as security incident disclosures.
Also, as tiffanyh pointed out, what's wrong with Github blog or is that exclusively for marketing fluff now? That would've been appropriate enough, without having to spend Sendgrid credits.
Re: GitHub is investigating unauthorized access to their internal repositories
#57Is Twitter/X the right channel to announce a security event like this? I ask because I don’t see anything posted on their official blog or status page. https://github.blog/ https://www.githubstatus.com/
Re: GitHub is investigating unauthorized access to their internal repositories
#58The security issue aside, seeing more companies push announcements like these on X as the only official source is a trend I'm not sure I like. I can understand the rationale, this feels lighter and not something that belongs on status.github.com or the blog. Maybe what's actually missing is an official channel for ephemeral stuff on a domain they own, somewhere between a status page and a tweet? Just sharing an obser…
Re: GitHub is investigating unauthorized access to their internal repositories
#59Re: GitHub is investigating unauthorized access to their internal repositories
#60https://pbs.twimg.com/media/HItbXhvW4AAMD8W?format=jpg&name=... All of their repos have been copied and are up for sale. Attackers are TeamPCP, the creators of the Shai-Hulud malware.
If that’s true and they do intend on shredding their copy on sale, what stops GitHub from buying it back themselves? (through a proxy, obv)