Wednesday , January 22 2025
Github

Recorded Future Report
Security Experts Urge IT to Lock Down GitHub Services

Recorded Future, a threat intelligence firm, has cautioned that malicious actors are using GitHub services more to carry out secret cyber-attacks and has advised IT teams to act.

Its new report, Flying Under the Radar: Abusing GitHub for Malicious Infrastructure, revealed the most popular GitHub services for threat actors.

Delay patching leaves about 50,000 Fortinet firewalls to zero-day attack

Fortinet customers must apply the latest updates, as almost 50,000 management interfaces remain vulnerable to the latest zero-day exploit. The...
Read More
Delay patching leaves about 50,000 Fortinet firewalls to zero-day attack

Daily Security Update Dated: 21.01.2025

Every day a lot of cyberattack happen around the world including ransomware, Malware attack, data breaches, website defacement and so...
Read More
Daily Security Update Dated: 21.01.2025

126 Linux kernel Vulns Allow Attackers Exploit 78 Linux Sub-Systems

Ubuntu 22.04 LTS users are advised to update their systems right away due to a crucial security patch from Canonical...
Read More
126 Linux kernel Vulns Allow Attackers Exploit 78 Linux Sub-Systems

CERT-UA alerts about “security audit” requests through AnyDesk

Attackers are pretending to be Ukraine's Computer Emergency Response Team (CERT-UA) using AnyDesk to access target computers. “Unidentified individuals are...
Read More
CERT-UA alerts about “security audit” requests through AnyDesk

Oracle Critical Pre-Release update addressed 320 flaw

Oracle Critical Patch Update Pre-Release Announcement shares details about the upcoming update scheduled for January 21, 2025. Note that this...
Read More
Oracle Critical Pre-Release update addressed 320 flaw

OWASP Reveils Top 10 Smart Contract Vulnerabilities for 2025

OWASP has released its updated list of the top 10 vulnerabilities in smart contracts for 2025. This guide highlights the...
Read More
OWASP Reveils Top 10 Smart Contract Vulnerabilities for 2025

Multiple Azure DevOps Vulns Allow To Inject CRLF Queries & Rebind DNS

Security researchers have found several vulnerabilities in Azure DevOps that could enable attackers to inject CRLF queries and carry out...
Read More
Multiple Azure DevOps Vulns Allow To Inject CRLF Queries & Rebind DNS

Intel holds 22 employees from one Bangladeshi University

Intel Corporation is a leading semiconductor chip manufacturer, employing at least 22 graduates from the Department of Applied Chemistry and...
Read More
Intel holds 22 employees from one Bangladeshi University

VPN Surge 1500% in USA after TikTok Shut Down

vpnMentor’s Research Team is monitoring the potential TikTok ban in the U.S., driven by national security and data privacy issues....
Read More
VPN Surge 1500% in USA after TikTok Shut Down

MITRE Launches D3FEND 1.0; The Milestone for Cybersecurity Ontology

MITRE launched D3FENDTM 1.0, a cybersecurity framework that provides a vocabulary and understanding of the cyber domain. D3FEND 1.0, funded...
Read More
MITRE Launches D3FEND 1.0; The Milestone for Cybersecurity Ontology

Between March and November 2023, GitHub Raw, GitHub Objects, and GitHub Pages were the most commonly used in attacks, according to an analysis of threat intelligence samples.

GitHub has nearly 100 million developers. This means it could be a big problem if it is misused.

Recorded Future stated that threat actors use it to hide malicious activity by blending in with benign network traffic. GitHub services are often unblocked in organizations and have high uptime. Additionally, they require minimal new account verification and offer limited detection possibilities for service providers.

The report said that it is a popular, inexpensive, and very effective platform for controlling malware and transferring data secretly.

Organizations need to consider GitHub in their threat modelling, Recorded Future argued.

“In the near term, defenders should pursue a service-based strategy by flagging or even blocking specific GitHub services that are not normally used in their environment and are known to be used maliciously,” the report noted.

“This should be paired with a context-based strategy based on the principle that only specific parts of a corporate environment necessitate interaction with particular GitHub services. In the longer term, organizations should allocate resources to better understand how GitHub and other code repositories are abused.”

It concluded with eight recommendations:

*Enhance visibility into GitHub with granular monitoring of all web and cloud traffic and context-aware policies enforced at the instance level
* Maintain an up-to-date asset inventory listing all users authorized to access GitHub
* Adapt detection strategies to align with the organization’s particular environment
* Deploy adaptive security policies, potentially alongside application allow-listing
* Protect GitHub accounts to prevent hijacking by threat actors to steal code or use as C&C infrastructure
* Continually assess effectiveness of threat detection capabilities by integrating scenarios of GitHub abuse into attack simulations
* Collaborate with GitHub to help it fight back against known malicious activity on the platform
* Perform proactive threat hunting to fight unknown instances of GitHub abuse

Check Also

Authority Denies
Hacker claim ransomware attack on Indonesia’s state bank BRI

Bank Rakyat Indonesia (BRI), the largest state bank by assets, has assured customers that their …

Leave a Reply

Your email address will not be published. Required fields are marked *