主要ニュース
5 媒体·7 本の記事

GitHub、従業員がインストールした悪意あるVS Code拡張機能により数千の内部コードリポジトリが盗まれたことを確認

GitHubは、数千件の内部コードリポジトリが侵害された不正アクセスについて調査を行っている。侵入経路は従業員がインストールした悪意あるVisual Studio Code拡張機能と特定されており、ハッカーが影響を受けたリポジトリからデータを窃取した。GitHub自身の管理外にある顧客ホストデータが影響を受けたという証拠は確認されていない。

以下のすべての記事をもとに作成しています。特定の一社によるものではありません。

自動翻訳です。元の記事はそれぞれの言語で書かれています。

各社の報じ方

  1. Ars Technica·
    In stunning display of stupid, secret CISA credentials found in public GitHub repo
  2. Hacker News·
    GitHub is investigating unauthorized access to their internal repositories
  3. TechMeme·
    GitHub says it's investigating "unauthorized access" to its internal repositories, and there's no proof of customer data outside its repositories being impacted (@github)
  4. Hacker News·
    GitHub Compromised
  5. TechMeme·
    GitHub confirms breach of ~3,800 repositories after one of its employees installed a malicious VS Code extension; TeamPCP claimed responsibility for the hack (Sergiu Gatlan/BleepingComputer)
  6. TechCrunch·
    GitHub says hackers stole data from thousands of internal repositories
  7. The Next Web·
    GitHub confirms hackers stole thousands of internal code repositories after employee installed a poisoned VS Code extension