GitHubが、マルウェアを含むコミットを利用した大規模なサイバー攻撃の標的となりました。この「Megalodon」と名付けられた攻撃により、5,000以上のリポジトリが影響を受けています。
同プラットフォームに対するこの攻撃では、多数のリポジトリへのコミットを通じて悪意のあるコードが配布されました。調査の結果、これは「TeamPCP」として知られる過去の攻撃キャンペーンの模倣犯によるものと特定されています。
GitHubが、マルウェアを含むコミットを利用した大規模なサイバー攻撃の標的となりました。この「Megalodon」と名付けられた攻撃により、5,000以上のリポジトリが影響を受けています。
同プラットフォームに対するこの攻撃では、多数のリポジトリへのコミットを通じて悪意のあるコードが配布されました。調査の結果、これは「TeamPCP」として知られる過去の攻撃キャンペーンの模倣犯によるものと特定されています。
AIによるレポート AIによって生成された画像
A critical Linux vulnerability known as CopyFail, tracked as CVE-2026-31431, allows attackers to gain root access on systems running kernels since 2017. Publicly released exploit code has heightened risks for data centers and personal devices. Ubuntu's infrastructure has been offline for over a day due to a DDoS attack, hampering security communications.
Seventy-three Microsoft open source packages were compromised late last week with malware that steals credentials from cloud services and developer tools. The malicious code activates when opened in AI coding agents.
AIによるレポート
More than 1500 user contributed packages in the Arch Linux User Repository were infected with malware.
Ubuntu's official Twitter account posted a now-deleted tweet promoting a fake AI agent that directed users to a cryptocurrency scam. The incident follows a five-day DDoS attack on Canonical's web services that ended earlier this month.
AIによるレポート
Meta disclosed that more than 20,000 Instagram accounts were stolen last week in a hacking operation that used an AI support bot.