buc.ci is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
https://www.reddit.com/r/freebsd/comments/1v6y5qe/dev_accidentally_commits_copilot_binary_to/
NB it was GitHub Copilot CLI, not to be confused with Copilot:
https://www.reddit.com/r/freebsd/comments/1v6y5qe/comment/ozu128h/ #AI #gibberish
RE: https://vt.social/@lina/116975435851200366
I deleted my #GitHub account since @huggingface.co stole my code (15 repos) in 2025, and happily moved to @Codeberg
Now I can’t opt-out. 🤦🏻♂️
To everybody working for or using #HuggingFace: I do not consent to any use of my code for training, calibration, (partial) extrusion or whatever you want to call your bullshit theft and grifting.
This means you effectively cannot use any part of this dataset for any means whatsoever, at least not without being a total arsehole.
Looks like Hugging Face scraped ~all of GitHub into an AI training dataset...
https://huggingface.co/spaces/HuggingFaceCode/in-the-stack
There is an opt-out link. You might want to use it.
@nixCraft thanks!
Popular amongst the shares: <https://www.reddit.com/r/linux/comments/1v00tfs/flathub_announces_migration_away_from_github_to/>
The Codeberg thing is not surprising. And once again the proof that "it's somebody else's computer".
GitHub is Microsoft is USA. GitHub is/was therefor restricted in places like Iran, North Korea, China, Russia, Syria, Crimea, etc.
Codeberg preventing usage of something under their ToS is similar, they can do whatever they want.
If you must avoid such situations don't use centralised solutions / somebody else's computer.
This is nuts. #huggingface have just scraped the entirety of #github. https://huggingface.co/spaces/HuggingFaceCode/in-the-stack
My view on the recent Codeberg drama:
https://gagliardoni.net/#20260724_codeberg_drama
Codeberg voting members have the right to decide the policy of their association, and I understand if a community is averse to anything that is AI- or Web3-related. I understand it, but I don't agree with it, because it's 2026, and if you still think you can just stick your head in the sand and wish for these ugly bad things to go away, well, I have bad news for you.
To me, this is a perfect recipe to relegate Codeberg to irrelevance. And we are already seeing the beginning of a new exodus.
Here is my conspiracy theory: the vote was pushed or manipulated from the inside by Big Tech. Whether this is true or not, one thing is sure: folks at Microsoft, GitHub, OpenAI etc. are now popping champagne.
#codeberg #opensource #foss #floss #libre #ai #llm #web3 #blockchain #crypto #cryptocurrency #antiai #luddism #eu #bigtech #politics #tech #censorship #github #microsoft #openai
And now, after banning vaguely-defined "LLM-generated code", Codeberg bans cryptocurrency projects. Discussion:
https://codeberg.org/Codeberg/org/pulls/1254
The specific ban is for "Content that harms the reputation of Codeberg, such as cryptocurrency related projects".
https://codeberg.org/Codeberg/org/commit/f383b648fd733ab88083dc390b91e77cd7589980
I think the reputation of Codeberg has been now harmed enough. When I originally escaped GitHub, I chose Codeberg exactly for the ethical stance and values. For me, anti-censorship is a non-negotiable ethical value. The folks at Codeberg have the right to run their org as they want. However, having now shown that they consider "censorship" good when it's about things they dislike, this made clear that their values and mine are not compatible (even if I dislike those same things, mind you).
Supporters of this ban say that this "draws a line", that "is not meant to be applied blanket-wide to all projects, only those which are harmful to the community", as if having constantly to worry about the next mood swing of Codeberg voting members were an acceptable Sword of Damocles for any reputable project. What's next? Banning US users? Banning software aligned with "capital-fascist" values? Open-source banking/wallet apps? Quantum computing tools? Robotics?
I'm moving off Codeberg, probably to Radicle. But I feel a bit sad, because Codeberg had the potential, in my opinion, to become the European alternative to GitHub, and they have made clear that they are not ready nor willing to become so. Which is fine: software is political, and everyone has the right to express their political stance.
But we still desperately need an alternative to GitHub.
#codeberg #drama #github #radicle #politics #opensource #bigtech #eu #europe #europa #usa #digitalsovereignty #ethics #censorship #crypto #web3 #blockchain #ai #llm #vibecoding
I was about to transfer my Abject project to Codeberg but can't now.
Codeberg seems to be more aligned with the OSS compared to the FL in FLOSS.
https://blog.codeberg.org/protecting-our-floss-commons-from-llms.html
Codeberg verbietet KI-Training und KI-Massenprojekte
Codeberg verbietet die Nutzung seiner Daten für KI-Training und plant, KI-generierte Massenprojekte auszuschließen.
#GitHub #IT #KünstlicheIntelligenz #OpenSource #Softwareentwicklung #news
Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign
#Packagist #GitHub #cPanel #CVE_2026_41940
https://socket.dev/blog/github-actions-abuse-powers-cpanel-and-whm-exploitation
CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈
Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way:
https://blog.packagist.com/securing-our-github-actions-workflows-with-zizmor/
#php #phpc #composerphp #github #githubactions #supplychainsecurity
seems there's an emerging trend in the #ai #llm space where people are producing tui interfaces or webapps in various frameworks and languages to keep an 👁️ on their #token usage.
i'm not talking like 1-2 finds rando on #github, countless ones. instead of writing a tool for monitoring your usage and costs. why not save your money and write a bash-script that polls the api endpoint (#zai #chatgpt #claude #deepseek) all have them.
From a 100 repos to only 20 left on #GitHub for now. I shall continue the purge tomorrow.
I was able to add a #Gitea runner with Docker. So now my several #Hugo repositories are already building in Gitea as I push changed, just like they did before on GitHub Actions (also using a shared workflow now).
Feels good.
If you use the `setup-uv` #GitHub #Action in your workflows, consider upgrading to version 9.0.0 soon.
This version changes the default behavior to store the downloaded #Python wheels from #PyPI in GHA Cache, shedding load from PyPI, especially relevant for frequent CI/CD runs.
The maintainers considered this a breaking change, hence the version bump, probably because it flips existing expectations.
If you expected that the Action was caching downloads before, now it actually does, so it's a logical fix in that regard.
Read more: https://github.com/astral-sh/setup-uv/releases/tag/v9.0.0
Codeberg community voted to ban AI-generated code in repositories:
https://codeberg.org/Codeberg/org/pulls/1253#issuecomment-19820434
I am a regular Codeberg user, left GitHub in 2019, and co-maintain Libre projects that saw very little if none at all AI in development.
And still I think this decision will backfire badly.
I, like most of Codeberg users, was not even aware that this discussion was in place, did not vote. This only passed because of the anti-AI Luddite crowd. Which, mind you, has a point, I have very conflicting feelings about AI myself, and I think that the current trajectory is quite worrying. But this is just a knee-jerk reaction that has clearly not been thought of well enough.
I applaude the philosophy, or the intent if you want, of not having Codeberg turn into another SlopHub. But this is fairy-tale wishful thinking. There is no way to reliably detect AI-generated code at scale in 2026.
I can already smell the mutual witch hunts across projects and "camps".
Anyway, I hope I'm wrong.
#codeberg #ai #llm #drama #opensource #ludd #luddism #antiai #libre #foss #floss #slop #github
@tante sorry, the "how will people enforce this" argument is real, dismissing it will not make it disappear.
I am a regular Codeberg user, left GitHub in 2019, and co-maintain Libre projects that saw very little if none at all AI in development.
And still I think this decision will backfire badly.
I, like most of Codeberg users, was not even aware that this discussion was in place, did not vote. This only passed because of the anti-AI Luddite crowd. Which, mind you, has a point, I have very conflicting feelings about AI myself, and I think that the current trajectory is quite worrying. But this is just a knee-jerk reaction that has clearly not been thought of well enough.
I applaude the philosophy, or the intent if you want, of not having Codeberg turn into another SlopHub. But this is fairy-tale wishful thinking. There is no way to reliably detect AI-generated code at scale in 2026.
I can already smell the mutual witch hunts across projects and "camps".
Anyway, I hope I'm wrong.
#codeberg #ai #llm #drama #opensource #ludd #luddism #antiai #libre #foss #floss #slop #github
I don't know what's more stupid: #OpenSSH using different authentication flow depending on whether you have a `.pub` file in addition to the private key or not, or #GitHub suddenly starting to reject one of the two valid RFC 4252 workflows.
people using #github in a professional environment (paying for), how's the experience nowadays?
Are you also impacted by throttling ?
«xAI stellt KI-Agen "Grok-Build" nach massivem Datenleck als Open Source auf GitHub:
xAIs Kommandozeilen-Tool "grok" hat massive Kritik ausgelöst, weil es beim Ausführen in einem Verzeichnis sämtliche Dateien auf xAIs Google-Cloud-Server hochlud.»
So viel zum Thema Suverenität von xAI. Klar ist, dass Open-Source ist schon länger auch Marketing der IT-Konzernen auf die meisten basieren.
#xai #datenleck #github #opensource #git #grok #grokbuild #googlecloud #ai #ki #x
GitHub gehört Microsoft. Zeit für einen Ausweg.
GitHub gehört seit 2018 Microsoft, unterliegt dem US Cloud Act und lässt Copilot seit April 2026 standardmäßig mit deinem Code trainieren, wenn du nicht widersprichst. Codeberg ist die naheliegende Alternative: gemeinnützig, europäisch, ohne Konzern im Rücken. Reden wir drüber!
https://www.chrislo.de/blog/2026-07-12-12-49-32-github-gehoert-microsoft-zeit-fuer-einen-ausweg/
#chrislo #DigitaleUnabhängigkeit #ServerInfrastruktur #GitHub #Codeberg #GitLab #Microsoft #OpenSource #CloudAct #Copilot #SelfHosting
New.
Socket: Compromised Injective SDK npm Package Exfiltrates Wallet Keys and Mnemonics https://socket.dev/blog/compromised-injective-sdk-npm-package @SocketSecurity #infosec #threatresearch #npm #GitHub
GitLost Attack Exploits GitHub Agentic Workflows Preview
🔗 https://cybersecurefox.com/en/gitlost-github-agentic-workflows-data-leak
#gitlost #github #agentic #workflows #ai #agents #prompt #injection #private #repositories
GitHub-Alternative für KI-Entwickler: Entire startet eigenes Git-Netzwerk
Entire startet ein eigenes Git-Netzwerk für die EU, USA und Australien. Das Start-up von Ex-GitHub-CEO Thomas Dohmke spiegelt auch GitHub-Repos.
#Git #GitHub #IT #OpenSource #Softwareentwicklung #Versionskontrolle #news
🚨 GitHub had two trust failures in the same week. Neither broke cryptography. Neither hacked AI.
They simply exploited the gap between what GitHub checks and what developers assume.
1️⃣ Git Hash Chain Malleability
A signed commit can be transformed into multiple different commit SHAs without the signing key.
✅ Same code
✅ Same signature
✅ Still shows Verified
❌ Different commit hash
2️⃣ GitLost (AI Prompt Injection)
GitHub's AI agent could be tricked into reading data from private repositories and posting it publicly through a malicious issue.
One attacks cryptographic trust.
The other attacks AI trust.
Different bugs. Same lesson:
"Verified" doesn't always mean what you think it means.
Full breakdown with technical details 👇
https://thecybersecguru.com/news/github-verified-commit-vulnerability/
#GitHub #Git #CyberSecurity #SupplyChainSecurity #DevSecOps #AppSec #AI #LLMSecurity #OpenSource #InfoSec
🤖 'GitLost' flaw: GitHub Agentic Workflows leak private repo data via a crafted public issue. No auth needed — attacker opens an issue, and if the agent has broad read access, private data is exfiltrated.
🔗 https://www.darkreading.com/cyber-risk/gitlost-leaks-private-data-github-agentic-workflows
#DataBreach #GitHub #DevSecOps #CyberSec
This was posted yesterday.
NOMA: GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos https://noma.security/blog/gitlost-how-we-tricked-githubs-ai-agent-into-leaking-private-repos/
More:
The Hacker News: Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data https://thehackernews.com/2026/07/public-github-issue-could-trick-github.html @thehackernews #GitHub #infosec #bots
15.0-RELEASE-p11, 15.1-RELEASE-p1, or 15-STABLE?
I'm grateful for the FreeBSD Foundation's use of GitHub.
& now there's YA reason: last week, #GitHub urged the FOSS community to *oppose* important #California legislation that places transparency and consumer rights requirements on deployment of LLM-gen-AI!
GitHub's tactic? Disinformation claiming #FOSS licenses are incompatible with Cal. Bus. & Prof. Code §22757 and California #SB1000 (which seeks to amend §22757).
Read the analysis: https://sfconservancy.org/blog/2026/jul/03/github-gen-ai-california-22757-ok-for-foss-license/
I just got this bill from #microsoft for #github usage. See if you can spot what is ridiculous about this bill.
Downloads from https://release-assets.githubusercontent.com/ are now speed limited or what?
Looks like, i can just download with a speed of 10 Mbit/s github uploaded releases.
Doesnt matter from which project i try to download assets, it's limited to ~1MB/s -.-
💡 Today is a perfect day to exercise your independence from #BigTech, and #GiveUpGitHub.
☣️ #GitHub is the equivalent of #Twitter and #Facebook for software development -- creators of the most enticing proprietary walled garden ever made for #FOSS developers.
Don't be stuck when Microsoft decides to change the rules on you.
Start today.
Awesome Digital Escape Tools is a curated collection of privacy-friendly, open-source, self-hosted, and secure software.
It features 220+ tools across 32 categories, with every entry linking to detailed information including features, screenshots, and more.
Contributions and suggestions are always welcome.
GitHub: https://github.com/abdomk1998/awesome-digital-escape-tools
#OpenSource #Privacy #SelfHosted #FOSS #GitHub #Linux #DeGoogle
New.
"The latest activity includes malicious npm releases affecting LeoPlatform and RStreams packages, GitHub Actions workflow abuse, and a related Go module compromise involving the Verana Blockchain project."
Socket: Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and GitHub Actions, Expands to the Go Ecosystem https://socket.dev/blog/miasma-mini-shai-hulud-hits-leoplatform-npm-packages-go-ecosystem @SocketSecurity #infosec #threatresearch #GitHub #npm #malware #JavaScript
FYI @ifin
The GitHub update was made yesterday: https://github.com/actions/checkout/commit/b9e0990d219a03df7633c93f6f005a8fecbcab22
More:
The Hacker News: GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns https://thehackernews.com/2026/06/github-updates-actionscheckout-to-block.html @thehackernews #infosec #GitHub
RE: https://infosec.exchange/@jkirk/116796238469020925
I know we like to all dunk on pastebin-with-devops but I will always hat tip every non-AI secure-by-design improvement an org takes!
More of this #gitHub team!
Angreifer nutzen GitHub als Malware-Schleuder: Laut Marc Stöckel verbreiten sie Trojaner über etwa 10.000 Repos. Vorgehen: bestehende Code-Projekte kopieren, Trojaner per Zip-Link in der Readme einschleusen – und kompromittierte Commits teils mehrfach am Tag erneut posten. GitHub reagiert offenbar nur auf Meldungen, nicht proaktiv. https://www.golem.de/news/github-als-malware-schleuder-trojaner-ueber-10-000-github-repos-verbreitet-2606-210032.html #Cybersecurity #GitHub #Malware
New post:
"A modular phishing infrastructure targeting multiple Mexican banks has been uncovered, abusing GitHub-hosted Pages, employing obfuscated scripts, and featuring a centralized credential exfiltration via SheetBest API, indicating a scalable and persistent multi-brand phishing operation."
Group-IB: GitBait: Phishing the Mexican Financial Sector https://www.group-ib.com/blog/gitbait-phishing-mexico-banking-finance/ #infosec #phishing #Github #cybercrime
New.
Check Point: From Stars to Upvotes: Fake Reputation Fueling a Crypto Clipboard Hijacker https://research.checkpoint.com/2026/from-stars-to-upvotes-fake-reputation-fueling-a-crypto-clipboard-hijacker/ #infosec #threatresearch #Rust #GitHub #YouTube
Manipulierte Red-Hat-npm-Pakete verbreiten neue Malware
#Cybersecurity #Cybersicherheit #Entwicklerwerkzeug #GitHub @jfrog #Malware #Miasma #NPM #RedHat #Linux #ShaiHulud #SupplyChain
https://netzpalaver.de/2026/06/14/manipulierte-red-hat-npm-pakete-verbreiten-neue-malware/
AI costs how much? GitHub Copilot users react to new usage-based pricing system.
Some report burning through their whole monthly
Archive: ia: https://s.faithcollapsing.com/iupsx
#ai #copilot #github #microsoft
https://arstechnica.com/ai/2026/06/ai-costs-how-much-github-copilot-users-react-to-new-usage-based-pricing-system/
Upcoming breaking changes for npm v12
#GitHub #npm
https://github.blog/changelog/2026-06-09-upcoming-breaking-changes-for-npm-v12/
#Github Security Advisories program is struggling under the load of new submissions. Delays in CVE assignment up to a month are being reported. Apparently, May 2026 was the highest volume month ever, and they are working through a backlog.
source: https://www.openwall.com/lists/oss-security/2026/06/10/9
It is not very hard to figure out what is going on: The amount of AI-assisted reports is flooding the systems. Considering the asymmetric nature of the situation (limited human resources processing increasing number of reports), it is unlikely the it is getting any better soon.
If just tracking and assigning issues is getting this hard, it can't bode well for actually fixing and patching them.
For the 2nd time in weeks, Microsoft packages laced with credential stealer
73 packages run self-replicating stealer as soon as they’re opened by an AI agent.
#ai #biz-&-it #github #microsoft #security #worms
https://arstechnica.com/security/2026/06/for-the-2nd-time-in-weeks-microsoft-packages-laced-with-credential-stealer/
New.
"The emails contained links to GitHub repositories masquerading as technical assignments or cryptocurrency-related projects. The instructions encouraged the target to clone the repository and open it in an editor such as VS Code or Cursor. A pre-configured task executes silently when the user opens the repository folder in the IDE, triggering platform-specific loaders that decode embedded payloads on Linux, macOS, and Windows."
Proofpoint: Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency https://www.proofpoint.com/us/blog/threat-insight/dont-fear-repo-unkdeaddrop-phishing-campaign-targets-developers-steal #threatresearch #infosec #phhishing #GitHub #Linux #MacOS #Windows11
#GitHub disabled 73 #Microsoft repositories across four of its GitHub organizations — the entire #Azure Functions org, the whole #Durable Task family, and a row of AI sample apps — in a 105-second sweep on June 5. The recompromised #durabletask package sits at the center, and the fingerprints point at the open-sourced #Miasma worm. #infosec
https://opensourcemalware.com/blog/miasma-reaches-azure
It seems #GitHub is blocking #Microsoft from using GitHub.
I hope you all had backups!
Access to the sassdawe/azure-functions-host repository has been disabled by #GitHub staff due to a terms of service violation.
When making content moderation decisions, we consider information from a variety of sources, including: account profile data, information contained in submitted reports/notices or discovered through our own voluntarily initiated investigations, and context around the contents of the repository.
If you wish to regain access to the disabled content or would like to dispute that a violation occurred and can provide additional information to show that a different decision should have been reached, please review our Appeal and Reinstatement Policy and submit a request via our form.
You may review our terms of service here: GitHub's Terms of Service
Please feel free to Contact GitHub Support if you have any questions.
Some happened to the source https://github.com/Azure/azure-functions-host
Apps die man z.B. über eine #github Seite auf seinem Android Smartphone installiert hat, lassen sich mit #obtainium installieren und auf aktuellem Stand halten.
Das muss einem schon gesagt werden.
The New Stack: GitHub Copilot’s usage-based billing is live: Here’s what you need to know https://thenewstack.io/github-copilot-token-billing/ @TheNewStack #GitHub #Microsoft #Copilot
Das gibt fuer viele Entwickler:innen heute ein boeses Erwachen, denn #Github #Copilot stellt heute auf ne Token-based Abrechnung um.
Bei einigen werden die monatlichen Rechnungen um das 25-fache steigen und zeigt wunderbar, wie die diversen Betreiber von AI-Fabs um Profitabilitaet kaempfen.
Es wird ein Hauen und Stechen!
https://thoughts.pivic.com/leave-github-a-few-quotes-about-why-its-more-than-a-good-idea
To leave GitHub is a good idea, for several reasons.
#GitHub #microsoft #capitalism #ArtificialIntelligence #ClimateCatastrophe #programming #AI
Malware-Slop: New Malicious npm Package Leaks Its Own GitHub Private Token
#npm #Claude #GitHub
https://www.ox.security/blog/malware-slop-new-malicious-npm-package-leaks-its-own-github-private-token/
🚨 CRITICAL: CVE-2026-9312 (SSRF) in GitHub Enterprise Server 3.16.0 – 3.21.0 lets unauth attackers access internal services via crafted uploads. Patch to 3.16.20+ ASAP! Details: https://radar.offseq.com/threat/cve-2026-9312-cwe-918-server-side-request-forgery--b1f49fcb #OffSeq #SSRF #GitHub #Vuln
Lawmakers Demand Answers as #CISA Tries to Contain Data Leak
https://krebsonsecurity.com/2026/05/lawmakers-demand-answers-as-cisa-tries-to-contain-data-leak/
RE: https://infosec.exchange/@cyberseckyle/116641588574197964
It should be noted that this "Megalodon" has nothing to do with the Fediverse API project or the old pink Megalodon Fediverse App.
"On May 18, 2026, an automated campaign codenamed megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories in a six-hour window. Using throwaway accounts and forged author identities (build-bot, auto-ci, ci-bot, pipeline-bot), the attacker injected GitHub Actions workflows containing base64-encoded bash payloads that exfiltrate CI secrets, cloud credentials, SSH keys, OIDC tokens, and source code secrets to a C2 server at 216.126.225.129:8443." #Mastodon #MastoAdmin #Megalodon #Github
https://www.stepsecurity.io/blog/megalodon-mass-github-actions-secret-exfiltration-across-5-500-public-repositories
GitHub Actions abused by Megalodon attack to slip malicious commits into 5,500 repos https://www.csoonline.com/article/4177124/github-actions-abused-by-megalodon-attack-to-slip-malicious-commits-into-5500-repos.html
GitHub Actions abused by Megalodon attack to slip malicious commits into 5,500 repos https://www.csoonline.com/article/4177124/github-actions-abused-by-megalodon-attack-to-slip-malicious-commits-into-5500-repos.html
Pixelfed has a known bug about the federation, and deleting Pixelfed posts and/or accounts don't delete them on remote servers.
Мой сонный разум породил подходящий рекламный слоган для #GitHub в последнее время:
«Я часть той силы, что вечно обещает SLA, но вечно производит баги».
Who guards the #infosec guards? #CISA embarrassed this week as attackers found a public #GitHub repository called "Private-CISA" w/ 844MB of plain-text passwords, AWS tokens & Entra @CISAgov ID SAML certs exposed since 11/25. HT @guedou of @gitguardian. https://cybersec.gitguardian.com/s/how-we-got-a-cisa-github-leak-taken-down-in-under-a-day-27502
In stunning display of stupid, secret CISA credentials found in public GitHub repo
SSH keys, plaintext passwords, other sensitive data had been up since November 2025.
Archive: ia: https://s.faithcollapsing.com/o2he7
#biz-&-it #brian-krebs #cisa #credentials #github #krebs #krebsonsecurity #leak #security #security-leak
https://arstechnica.com/information-technology/2026/05/in-stunning-display-of-stupid-secret-cisa-credentials-found-in-public-github-repo/
Attack on GitHub: Data from 3800 internal repositories stolen
GitHub has confirmed an attack via an extension for Visual Studio Code. The stolen data is apparently for sale on a cybercrime forum.
#GitHub #IT #Security #Softwareentwicklung #Versionskontrolle #news
RE: https://techhub.social/@Techmeme/116606089296164399
Remember this whenever you hear claims that your data is secure on some system or other that you do not own and control.
Like all that additional data governments want to gather via the slippery slope of “age verification” in the EU.
The only data that is actually secure on a third party is data you haven’t shared with the third party.
Hence: data minimisation.
Had I mentioned GDMR yet today? Because I feel I might have. But hey, here it is again:
#data #security #privacy #GDMR #microsoft #github #hack
AodeRelay boostedGitHub confirms breach of ~3,800 repositories after one of its employees installed a malicious VS Code extension; TeamPCP claimed responsibility for the hack (Sergiu Gatlan/BleepingComputer)
https://www.bleepingcomputer.com/news/security/github-confirms-breach-of-3-800-repos-via-malicious-vscode-extension/
http://www.techmeme.com/260520/p14#a260520p14
Let's move all of our internal code, pipelines, secrets and tokens for external systems to someone. It's free and everyone does - it must be awesome. Welcome to 2026!
info on the github breach appears to only be available on xitter 🙄 , I fished it out for you.
Canada’s Bill C-22 would weaken protections on private messages
Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP
📢⚠️ New: Grafana Labs, the open source analytics and visualization company, says hackers stole its source code after gaining access to a GitHub token and later demanded a ransom.
Read: https://hackread.com/grafana-source-code-theft-rejected-ransom-demand/
New.
Socket: Packagist Urges Immediate Composer Update After GitHub Actions Token Leak https://socket.dev/blog/packagist-urges-immediate-composer-update @SocketSecurity #infosec #GitHub #vulnerability