GitHub dismissed security reports on flaws now exploited by supply-chain worm, researchers say

Alexander Martin reports: GitHub rejected two formal vulnerability reports identifying design flaws that researchers say are enabling variants of the Shai-Hulud supply-chain worm to infect and compromise hundreds of software packages and developer accounts worldwide. The reports, submitted by threat intelligence group Deep Specter Research through GitHub’s bug disclosure channel on HackerOne, were both closed…

Introduction to Malware Binary Triage (IMBT) Course

Looking to level up your skills? Get 10% off using coupon code: MWNEWS10 for any flavor.

Enroll Now and Save 10%: Coupon Code MWNEWS10

Note: Affiliate link – your enrollment helps support this platform at no extra cost to you.

Source

Article Link: https://databreaches.net/2026/06/17/github-dismissed-security-reports-on-flaws-now-exploited-by-supply-chain-worm-researchers-say/?pk_campaign=feed&pk_kwd=github-dismissed-security-reports-on-flaws-now-exploited-by-supply-chain-worm-researchers-say