GitHub discloses breach of 3,800 internal code repositories.
ID: de23e362-e526-59e2-adc5-163418215296
STIX ID: report--de23e362-e526-59e2-adc5-163418215296
Feed Name: The CyberWire
GitHub confirmed a compromise of an employee device via a poisoned VS Code extension that GitHub says affected roughly 3,800 internal repositories and is being claimed/sold by the TeamPCP threat actor; Microsoft separately used a court order to disrupt the Fox Tempest malware-signing-as-a-service, which enabled threat actors to sign and distribute malware (including info‑stealers and ransomware) and named Vanilla Tempest as a co-conspirator. The report also contains unrelated business news about Akamai acquiring LayerX.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
