
A significant security flaw in GitHub, which could also impact GitLab, has been identified as allowing threat actors to distribute malware using URLs associated with Microsoft repositories. This flaw involves the misuse of GitHub comments, where files added to comments are uploaded to GitHub's CDN, appearing as if they originate from legitimate repositories like Microsoft. This method creates highly convincing phishing lures, exploiting the trust in URLs from reputable sources. The issue has been highlighted as either a flaw or a potential design decision, with the only preventative measure being the disabling of comments on GitHub accounts to avoid abuse.







ceo of github follows my other account! @ashtom, can you please put out a model repository function for @github. some of us use a product called @huggingface but its reliability has been awful. This could be a good opportunity for you to expand your business into this high… https://t.co/YRKbf6xgze
Hackers Create Legit Phishing Links With Ghost GitHub, GitLab Comments: https://t.co/Cpx9bc9BiE by darkreading #infosec #cybersecurity #technology #news
GitHub Comments Abused to Spread Malware in Fake Microsoft Repositories https://t.co/YJZPGJp1GM