Risky Business #839 -- TeamPCP stole GitHub's internal repos
Developer platform security model faces scrutiny as internal repository compromise demonstrates critical trust boundaries in software development infrastructure.
Summary written by editorial AI · Source link below
On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news. They cover:
TeamPCP breached GitHub’s internal repos. Now what? Some absolute plonker glued Coruna to a hijacked npm package CISA is worried about about open source and wants third party submissions for KEV AI infrastructure is “systemically” insecure Much, much more
This week’s episode is sponsored by allowlisting vendor Airlock Digital. Airlock’s founders David Cottingham and Da
External link — opens at Risky Business in a new tab.
More from the Threat Intel Desk
- Attackers conceal phishing lures using invisible Unicode characters1d
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication1d
- Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner1d
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials2d
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain2d