惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
J
Java Code Geeks
F
Fortinet All Blogs
Blog — PlanetScale
Blog — PlanetScale
P
Proofpoint News Feed
U
Unit 42
B
Blog
宝玉的分享
宝玉的分享
腾讯CDC
Microsoft Azure Blog
Microsoft Azure Blog
酷 壳 – CoolShell
酷 壳 – CoolShell
Last Week in AI
Last Week in AI
博客园 - Franky
博客园 - 三生石上(FineUI控件)
人人都是产品经理
人人都是产品经理
Martin Fowler
Martin Fowler
博客园_首页
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
云风的 BLOG
云风的 BLOG
L
LangChain Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Y
Y Combinator Blog
The GitHub Blog
The GitHub Blog
博客园 - 叶小钗

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers
GitHub Says 3,800 Repositories Breached—TeamPCP Hackers D...
Davey Winder · 2026-05-20 · via Forbes - Innovation
GitHub logo featuring cat.

GitHub confirms 3,800 repositories breached.

Anadolu via Getty Images

GitHub, the cloud-based hosting service used by software developers to store and manage code, has confirmed a major security incident involving an employee. A May 20 posting to the X social media platform by the GitHub account has stated that “the attacker’s current claims of 3,800 repositories are directionally consistent with our investigation so far.” The good news, if you can call it that, is that the investigation appears to suggest that the TeamPCP hackers have only exfiltrated GitHub-internal repositories. The bad news, however, is that TeamPCP reckons it now has access to GitHub's source code.

ForbesMicrosoft Confirms Active 0-Day Exploit—Check Emergency MitigationBy Davey Winder

TeamPCP Hacking Group Put Stolen GitHub Data Up For Sale

The hacking of GitHub, which Microsoft acquired for $7.5 billion in 2018, is a big deal no matter which way you cut it. Used by 4 million organizations and 180 million developers, the cloud platform has more than 400 million code repositories in total. You might think, therefore, that a breach involving just 3,800 of them isn’t all that newsworthy. But context is everything, and in this case, that context comes in twofold: the repositories appear to be internal GitHub ones, and the breach itself was inadvertently enabled by a GitHub employee.

The compromise was detected by GitHub security teams on May 19, sparking an immediate investigation. GitHub said then that it had “no evidence of impact to customer information stored outside of GitHub’s internal repositories,” but was alert and closely monitoring for any follow-on activity.

Currently, no further information regarding what happened beyond it involving the compromise of a GitHub employee device after they installed a malicious VS Code extension is available. This is not unusual while the investigation is ongoing. GitHub has said it will publish a full report once the investigation is completed.

MORE FOR YOU

“We moved quickly to reduce risk,” a GitHub spokesperson said, “critical secrets were rotated yesterday and overnight with the highest-impact credentials prioritized first.” TeamPCP member “box turtle” has claimed, however, that “Github knew for hours, they delayed telling you and they wont be honest in the future,” regarding the breach.

TeamPCP has posted a for-sale notice on a notorious hacking forum that said it wants at least $50,000 for the stolen data, including “Github’s source code and internal orgs,” adding that “no low-ball offers will be accepted.” That posting also stated that TeamPCP is not holding GitHub to ransom but rather just looking to sell to a single buyer after which the data will be shredded. The hacking group warned, however, that “if no buyer is found we will leak it free.”

GitHub users should remain alert to any follow-on threats that leverage fear, uncertainty and doubt about the TeamPCP breach to attempt to access accounts through targeted phishing attacks. GitHub says that users should enable two-factor authentication and add a passkey for good measure by way of account protection.