Github员工遭污染的VSCode扩展入侵

从 赛博安全威胁情报 看到的,可以说算转载了 Github的某位员工因为受污染VsCode扩展,导致核心3800个内部仓库泄露。其中包括Copilot的源码,CodeQL的算法,还有Actions运行时和整个计费系统 原帖: X 上的 GitHub:“We are investigating una...
Github员工遭污染的VSCode扩展入侵
Github员工遭污染的VSCode扩展入侵

赛博安全威胁情报:disguised_face:看到的,可以说算转载了 :face_holding_back_tears:

Github的某位员工因为受污染VsCode扩展,导致核心3800个内部仓库泄露。其中包括Copilot的源码,CodeQL的算法,还有Actions运行时和整个计费系统

原帖:X 上的 GitHub:“We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely” / X

最新的贴文,目前事情还在详细调查,敬请期待:X 上的 GitHub:“1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub’s internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version,” / X

HIuP4K5W8AE6GR3.jfif

1 个帖子 - 1 位参与者

阅读完整话题

来源: LinuxDo 最新话题查看原文