Investigating unauthorized access to GitHub-owned repositories
The GitHub Blog315 字 (约 2 分钟)
85
GitHub confirmed unauthorized access to internal repositories due to a compromised third-party VS Code extension, but customer data remained unaffected with immediate remediation and ongoing investigation.
入选理由:攻击通过被污染的第三方VS Code扩展(nrwl/nx-console)入侵员工设备,该扩展存在GHSA-c9j4-9m59-847w漏洞
FeaturedArticle#GitHub Security#VS Code Extension#Data Breach#Incident Response英文