Saturday, August 9, 2025
NewsWave
No Result
View All Result
  • Home
  • World
  • USA
  • Business
  • Sports
  • Entertainment
  • Technology
Login
  • Home
  • World
  • USA
  • Business
  • Sports
  • Entertainment
  • Technology
Login
No Result
View All Result
Login
NewsWave
No Result
View All Result
Home Technology

GitHub malware spreads by hackers spoofing Microsoft files

22 April 2024
in Technology
0
GitHub malware spreads by hackers spoofing Microsoft files
Share on FacebookShare on Twitter
How does this make you feel?



There have been reports of hackers finding a way to upload malware to GitHub, making it appear as if it was hosted and distributed by legitimate operators. McAfee cybersecurity researchers recently discovered the LUA malware loader being distributed through a repository that seemed to belong to Microsoft on GitHub.

The malware uploaded to GitHub has unique features that make it difficult to detect. For example, a link to the malware may appear as follows: https://github[.]com/microsoft/vcpkg/files/14125503/Cheat.Lab.2.7.2.zip. However, attempting to locate the .zip file in the vcpkg library directly will yield no results.

It seems that users can upload files when leaving a comment on a commit or issue. These files are automatically uploaded, generating a link like the one mentioned above. Users can post and delete the comment quickly, but the file will remain uploaded and accessible, even without posting the comment.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features, and guidance your business needs to succeed!

It is unclear if this behavior is a bug or an intentional feature on GitHub’s part. BleepingComputer reports that victim companies have limited options to protect themselves from impersonation. Disabling comments is a possible solution, but it can create more issues as legitimate users often use comments to report bugs or provide suggestions. Furthermore, comments can only be disabled for a maximum of six months at a time.

More from TechRadar Pro



Source link

🪄 Creating a simple explanation...

Tags: FilesGitHubhackersmalwareMicrosoftspoofingspreads
Previous Post

People Complaining About NHS Appointments Being Too Quick Resurfaces

Next Post

Indonesia’s Top Court Clears Way for Prabowo’s Presidency

Related Posts

James Lovell, the steady astronaut who brought Apollo 13 home safely, has died
Technology

James Lovell, the steady astronaut who brought Apollo 13 home safely, has died

by My News Wave
9 August 2025
0

James Lovell, a key figure in humanity's first moon landing and commander of the Apollo 13 mission, passed away at 97, as confirmed by NASA. Acting NASA Administrator Sean Duffy expressed condolences, highlighting Lovell's inspiring legacy and his role in turning a potential disaster into a significant learning experience for the nation. Want More Context? 🔎

Read more
CyberArk and HashiCorp Flaws Enable Remote Vault Takeover Without Credentials
Technology

CyberArk and HashiCorp Flaws Enable Remote Vault Takeover Without Credentials

by My News Wave
9 August 2025
0

Cybersecurity researchers have identified 14 vulnerabilities, collectively named Vault Fault, in enterprise secure vaults from CyberArk and HashiCorp. If exploited, these flaws could enable remote attackers to compromise corporate identity systems and access sensitive enterprise secrets and tokens. Want More Context? 🔎

Read more
Smartwatches Offer Little Insight Into Stress Levels, Researchers Find
Technology

Smartwatches Offer Little Insight Into Stress Levels, Researchers Find

by My News Wave
8 August 2025
0

A study reported by The Guardian reveals that smartwatches are ineffective at accurately measuring stress levels, often mistaking excitement for overwork. Researcher Eiko Fried emphasizes the minimal correlation between smartwatch data and self-reported stress, cautioning users to not rely on these consumer devices for insights into their mental states. Want More Context? 🔎

Read more
Millions Flock To Grow Virtual Gardens In Viral Roblox Game
Technology

Millions Flock To Grow Virtual Gardens In Viral Roblox Game

by My News Wave
8 August 2025
0

Grow a Garden, a Roblox game developed by a 16-year-old, has set a record with over 21.6 million concurrent players, surpassing Fortnite, as players engage in low-stress gardening activities. Its rise in popularity coincided with the delay of Grand Theft Auto 6, sparking discussions on the legitimacy of casual gaming in the broader gaming community. Want More Context? 🔎

Read more
AI Industry Horrified To Face Largest Copyright Class Action Ever Certified
Technology

AI Industry Horrified To Face Largest Copyright Class Action Ever Certified

by My News Wave
8 August 2025
0

AI industry groups are urging an appeals court to block a significant copyright class action lawsuit against Anthropic, claiming it could financially devastate the AI sector with up to 7 million potential claimants. Anthropic argues that the district court's class certification was rushed and flawed, warning that the potential liability could coerce them into settling, setting a troubling precedent for the future of generative AI. Want More Context? 🔎

Read more
ChatGPT is bringing back 4o as an option because people missed it
Technology

ChatGPT is bringing back 4o as an option because people missed it

by My News Wave
8 August 2025
0

OpenAI has reinstated GPT-4o in ChatGPT just a day after the rollout of GPT-5, allowing Plus users to choose their preferred model amid user dissatisfaction with the new version's perceived drop in quality and personality. CEO Sam Altman acknowledged the feedback, indicating that the company will monitor usage as it considers the future of legacy models. Want More Context? 🔎

Read more
NewsWave

News Summarized. Time Saved. Bite-sized news briefs for busy people. No fluff, just facts.

CATEGORIES

  • Africa
  • Asia Pacific
  • Australia
  • Business
  • Canada
  • Entertainment
  • Europe
  • India
  • Middle East
  • New Zealand
  • Sports
  • Technology
  • UK
  • USA
  • World

LATEST NEWS STORIES

  • Justin Fields injury update: Jets QB ‘up and down as a passer’ ahead of preseason opener
  • A stronger political stand from Indonesia could – Middle East Monitor
  • Killer Beez gang boss Joshua Masters guilty of child endangerment after dangerous Auckland ride
  • About Us
  • Disclaimer
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact Us

Copyright © 2025 News Wave
News Wave is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • World
  • USA
  • Business
  • Sports
  • Entertainment
  • Technology

Copyright © 2025 News Wave
News Wave is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In