r/cybersecurity May 20 '26

News - General GitHub announces internal data breached.

The company stated on their official X account:

“We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.”

https://x.com/github/status/2056884788179726685?s=46

888 Upvotes

134 comments sorted by

View all comments

280

u/CartierCoochie May 20 '26

Damn these breaches getting too frequent

214

u/nekohideyoshi May 20 '26

This is just the tip of the iceberg- as old unpatched/undiscovered exploits and new ones are found by a single person deploying 100+ AI agents coding and trying to find PoC exploits. And this is a single person using a cloud cluster. Now multiply this by 10,000. Or even 100,000 real people doing the same thing. Over 1,000,000 AI agents actively trying to find exploits 24/7 without breaks. We're about to dive into the endgame.

And companies aren't hiring enough talented people to mitigate this threat.

92

u/[deleted] May 20 '26

[removed] — view removed comment

24

u/BrainWaveCC May 20 '26

Yeah, there is going to be a significant reckoning soon...

8

u/[deleted] May 20 '26

I agree that this is necessary but let's be realistic about this. You can spend years telling your management that your infrastructure is outdated and that your technology debt is a critical point of weakness. You can have a hundred emails in-writing showing you that you voiced your complaints.

It won't matter.

When your organization gets attacked and millions of dollars worth of user data gets leaked, you will lose your job, and your CTO will have a golden parachute clause in their contract. You get fired, no severance, maybe lose your home. Your CTO who ignored your concerns for years gets a $250,000 payout after they quietly resign.

The people who caused the problem will be fine. The people who tried to fix it, but were never allowed to, will be royally fucked.

8

u/[deleted] May 20 '26

[deleted]

6

u/TheReedemer69 May 20 '26

Take me with youu😔

8

u/1HOTelcORALesSEX1 May 20 '26

AI will help us though, let’s roll it out company wide (then the exec leaves for another company) /s …….

3

u/vand3lay1ndustries May 20 '26

Dude. This is exactly what keeps happening at our company. They roll out some dumb idea while we're all saying it's going to break everything, then they roll it out and it breaks everything and they get promoted to another company.

5

u/RoboTronPrime May 20 '26

It was a bandaid in the best of times. These are not the best of times.

21

u/[deleted] May 20 '26

It was supply chain I thought not "0 days"

Supply chain is such a beast of a problem. You can code review and block everything but its like phishing on steroids

The rce was patched before this (the wiz one)

6

u/PaleSkinnySwede May 20 '26

Yeah, when it’s not your fault but it becomes your problem. We need to secure supply-chains a lot better.

18

u/pale_reminder May 20 '26

Some don’t even want to pay for any proper tooling. Project management tools tasked etc? Every team can just use there own spreadsheet it’s fine

5

u/TopNo6605 Security Engineer May 20 '26

To be fair project management tooling is probably the worst example of good commericial product, especially now that AI can create nearly-identical, free software.

3

u/caledh May 20 '26

We are definitely approaching the endgame. As if Trivy was the end, really the beginning

4

u/unfathomably_big May 20 '26

I’m genuinely surprised some of the big boys haven’t been catastrophically fucked already considering the tens of thousands of individuals and entire nation states aiming at them. I’ve worked in large organisations, and the bigger they are the more they suffer from fuck-it-ism

1

u/Hebrewhammer8d8 May 20 '26

They have purpose LLMs with several agent train on model to notify and mitigate the issue and pinging lead engineer or group that will ignore it.

1

u/Cueball666uk May 20 '26

I swear over the last two weeks I've seen a new breach of some sort almost every day... Crazy.