Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Microsoft Addresses GitHub Security Breach Amid Ongoing Probe

Microsoft Addresses GitHub Security Breach Amid Ongoing Probe

Posted on June 9, 2026 By CWS

Microsoft has taken steps to address a recent security breach that impacted several GitHub repositories. On Monday, the tech giant confirmed that it temporarily removed some repositories following the discovery of a security incident where 73 open-source projects were compromised. The breach involved injecting an information-stealing malware into the project code.

Microsoft’s Response to the Breach

A Microsoft representative emphasized the company’s commitment to protecting its users and the broader ecosystem. “We have temporarily taken down certain repositories to investigate potentially harmful content,” the spokesperson explained. While some repositories have been restored after thorough review, others will remain offline as the investigation continues.

Microsoft has also alerted a select group of customers who might have downloaded content from the affected repositories. The company assured that it would continue to monitor the situation and directly contact customers if further actions are necessary.

Details of the Miasma Campaign

This incident is part of a larger software supply chain campaign known as Miasma. Recently, Microsoft restricted access to several open-source projects on GitHub after reports of their compromise. Among the affected projects was “durabletask,” a Python package targeted by the cybercrime group TeamPCP to deploy an information stealer aimed at Linux systems.

Further investigation into the Miasma payload revealed the ability to execute code automatically when developers open the repository using AI-powered coding tools or integrated development environments (IDEs). This is part of a continuous strategy to plant malware in widely used open-source packages, potentially affecting downstream users.

Adapting Threats and Future Outlook

Recent findings indicate that the threat actors are experimenting with new payload delivery methods. Earlier packages used startup hooks to run a JavaScript stealer, but newer variants employ different tactics. These include Trojanized native extensions and modified startup hook loaders, which separate the malware loader from the payload to evade static analysis detection.

Despite the methods employed, the malware’s objective remains the same: targeting developer workstations and CI/CD environments to capture sensitive data and transmit it to a public GitHub repository. A notable aspect of the bioinformatics package is its ability to bypass AI-powered analysis tools through adversarial prompt injections.

Kirill Boychenko, a researcher at Socket, highlighted that the Hades branch of the Miasma campaign exemplifies a rapidly evolving supply chain threat. As these attacks continue to develop, monitoring and safeguarding against such vulnerabilities remain critical for developers and organizations worldwide.

The Hacker News Tags:AI security, Cybersecurity, GitHub, Malware, Miasma, Microsoft, Open Source, security breach, software supply chain, TeamPCP

Post navigation

Previous Post: Microsoft Entra Logs Expose Risky Agent Activities
Next Post: OpenSSL Addresses Critical Vulnerability with AI Assistance

Related Posts

17,500 Phishing Domains Target 316 Brands Across 74 Countries in Global PhaaS Surge 17,500 Phishing Domains Target 316 Brands Across 74 Countries in Global PhaaS Surge The Hacker News
FBI Alerts: Russian Hackers Phish WhatsApp, Signal Users FBI Alerts: Russian Hackers Phish WhatsApp, Signal Users The Hacker News
Unpatched Versa Concerto Flaws Let Attackers Escape Docker and Compromise Host Unpatched Versa Concerto Flaws Let Attackers Escape Docker and Compromise Host The Hacker News
Fragnesia Linux Kernel Vulnerability Allows Root Access Fragnesia Linux Kernel Vulnerability Allows Root Access The Hacker News
CISA Retires 10 Emergency Cybersecurity Directives Issued Between 2019 and 2024 CISA Retires 10 Emergency Cybersecurity Directives Issued Between 2019 and 2024 The Hacker News
Hard-Coded Credentials Found in HPE Instant On Devices Allow Admin Access Hard-Coded Credentials Found in HPE Instant On Devices Allow Admin Access The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Anthropic Unveils Claude Fable 5: Secure Mythos-Class AI
  • Hades Attack Targets PyPI: 19 Packages Compromised
  • North Korean Hackers Exploit GitHub to Target Developers
  • OpenSSL Addresses Critical Vulnerability with AI Assistance
  • Microsoft Addresses GitHub Security Breach Amid Ongoing Probe

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Anthropic Unveils Claude Fable 5: Secure Mythos-Class AI
  • Hades Attack Targets PyPI: 19 Packages Compromised
  • North Korean Hackers Exploit GitHub to Target Developers
  • OpenSSL Addresses Critical Vulnerability with AI Assistance
  • Microsoft Addresses GitHub Security Breach Amid Ongoing Probe

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark