GitHub disabled 73 repositories across four Microsoft organizations after attackers used a compromised contributor account to push a malicious commit to Azure’s durabletask repository. Researchers linked the incident to the broader Miasma supply-chain campaign, which previously hit Red Hat’s npm ecosystem. The payload targeted developers through AI coding tools to harvest credentials, highlighting growing risks in developer workflows. Recommended responses include token rotation and pinning GitHub Actions to commit SHAs.
Trending
- India Exempts Foreign Investors From Bond Taxes, Opens $50B Inflow Pathway
- India Unveils Bond Reforms to Attract Foreign Capital and Support Rupee
- India Auto Retail Hits Record in May as EV Share Tops 11%
- India’s Auto Market Hits Record High in May, EVs Drive Past 11% Share
- IMF Chief Warns World Is Unprepared for Next Global Economic Crisis
- IMF Chief Warns Global Economy Unprepared for Next Crisis as Shocks Pile Up
- Piyush Goyal Sees Limited Risk From Proposed 12.5% US Tariff, Expects Trade Deal ‘Soon’
- Piyush Goyal Sees Limited Risk From Proposed 12.5% US Tariff, Expects Trade Deal ‘Soon’

