- github.blog
Don’t stop early: Case-folding source code at memory speed
GitHub’s engineering team revealed how they optimized case-folding for Blackbird, their code search engine, by removing early-exit branches in ASCII processing. This change boosted performance from 3 …
- Securitytechrepublic.com
GitHub Automatically Holds Suspicious Actions Runs, but Repository Owners Must Approve Them - TechRepublic
GitHub will now pause potentially malicious Actions workflow runs in public repositories until an authorized collaborator approves them. The safeguard, announced July 28, 2026, targets attacks using c…
- gbhackers.com
Attackers Abuse GitHub Actions Workflow to Publish Provenance-Signed npm Malware - gbhackers.com
On July 14, 2026, attackers compromised the @asyncapi npm organization by abusing GitHub Actions workflows to publish five backdoored packages with valid cryptographic provenance. The attack executed …

- Featuregithub.blog
Tame Dependabot: Group your updates, slow the cadence, keep security fast
GitHub demonstrated how Microsoft’s GCToolkit reduced Dependabot noise by grouping updates into monthly batches and slowing cadence from daily to monthly, cutting review and CI cycles. The change invo…
- Featurethehackernews.com
GitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package Adoption - The Hacker News
GitHub introduced a 3-day cooldown in Dependabot for version updates to reduce exposure to poisoned packages, while security updates remain immediate. The default balances attack window reduction with…
- Featuregithub.blog
Stacked pull requests are now in public preview - The GitHub Blog
GitHub introduced stacked pull requests in public preview, allowing teams to break large changes into ordered, reviewable layers. Each pull request can be reviewed independently, with the entire stack…
- medianama.com
GitHub takes down BitChat after Home Ministry order - MediaNama
India’s Ministry of Home Affairs directed GitHub to remove repositories for Bitchat, a decentralized Bluetooth mesh messaging app, citing unauthorized access and national security concerns under the I…

- github.blog
Claude Opus 5 is now available in GitHub Copilot - The GitHub Blog
GitHub Copilot now supports Anthropic’s Claude Opus 5, optimized for complex, multi-step coding tasks like autonomous changes and regression verification. The model includes enhanced cyber-content saf…
- smartcompany.com.au
Jack Dorsey takes on Slack and GitHub with new AI workplace platform Buzz - SmartCompany
Block, led by Jack Dorsey, launched Buzz, an AI-first workplace collaboration platform combining messaging, project management, and software development. Buzz integrates AI agents directly into team w…
- business-standard.com
GitHub Sponsors crosses $100 mn milestone as corporate funding accelerates - Business Standard
GitHub Sponsors reached $100 million in contributions, driven by accelerated corporate sponsorships that now support over 70,000 open-source maintainers globally. The milestone reflects growing corpor…
)
- kucoin.com
AMD Listed Anthropic as a Customer in GitHub Code, Suggesting Potential AI Partnership - KuCoin
A GitHub code file by AMD’s VP of AI Software listed Anthropic as a top-priority customer, matching Meta’s status. Anthropic is hiring ROCm engineers and evaluating AMD’s software stack ahead of AMD’s…

- tech-insider.org
OpenCode Hits 160K GitHub Stars, Tops Coding Tools [2026] - tech-insider.org
OpenCode, an MIT-licensed terminal-based coding agent, surged to the top of LogRocket’s July 2026 AI dev tool rankings with 160,000 GitHub stars and 7.5M monthly active developers. Its rise was cataly…

- helpnetsecurity.com
Threat actor impersonated hundreds of brands on GitHub to push infostealer malware - Help Net Security
A financially motivated Russian-speaking threat actor is impersonating 292 brands on GitHub to distribute a smash-and-grab infostealer malware disguised as legitimate software downloads. The campaign,…

- mk.co.kr
The targets of hackers' attacks are expanding beyond corporate information and communication network.. - 매일경제
South Korean police reported a leak of GitHub Personal Access Tokens (PATs), enabling attackers to access private repositories and steal sensitive data like API keys and database passwords. The leak c…

- cyberpress.org
GitHub Copilot Backends Produce Unsafe Code Outputs Through Workflow Jailbreaks - cyberpress.org
Researchers demonstrated a multi-turn workflow exploit that bypasses GitHub Copilot’s safety guardrails by framing harmful objectives as benchmark-improvement tasks. All four tested backends (Claude S…

- Featuregithub.blog
OpenAI’s GPT-5.6 Sol, Terra, and Luna are now available in GitHub Copilot - The GitHub Blog
GitHub Copilot now supports OpenAI’s GPT-5.6 family with three variants—Sol, Terra, and Luna—each optimized for different coding tasks. The models are available across most Copilot SKUs, with Enterpri…
- Securityinfoworld.com
GitHub’s public APIs are becoming an enterprise reconnaissance tool - InfoWorld
Researchers uncovered sustained campaigns using GitHub’s public APIs and ghost accounts to profile enterprise software environments, blending into normal developer activity. Attackers map organization…

- Featuregithub.blog
Ask Copilot for a repository overview - The GitHub Blog
GitHub Copilot now generates high-level overviews of unfamiliar repositories, summarizing purpose, technologies, and contribution guidelines. If a repository lacks a README, Copilot can create one. Th…
- cioafrica.co
Kaspersky Finds Widespread GitHub Actions Flaws - CIO Africa
Kaspersky’s analysis of 130,000 CI/CD pipelines in 30,000 GitHub repositories revealed over 250,000 security misconfigurations, with only 10% of repos free of alerts. High-risk flaws were found in 200…

- stepsecurity.io
GitHub Secret Scanning Public Monitoring for Enterprises: Coverage and Gaps - StepSecurity
GitHub launched public monitoring for secret scanning, scanning all public content on github.com in real time to detect leaked secrets tied to enterprises via GitHub's identity layer. Available at no …
.png)
- zamin.uz
GitHub's Unexpected Move: Proposal to Store Software Code on CDs - Zamin.uz
GitHub teased a concept allowing users to obtain physical CD-ROM copies of public repositories, framing it as a nod to 'physical ownership' of digital assets. The move blends satire with a critique of…

- cxodigitalpulse.com
Entire Appoints Former GitHub APAC Field CTO Karthik Rameshkumar as Field CTO for India Expansion - CXO Digitalpulse
Entire hired Karthik Rameshkumar, former GitHub APAC Field CTO, as its first Field CTO for India to lead developer adoption and AI-native infrastructure initiatives. The move underscores Entire’s push…

- arcticwolf.com
Security Bulletin: GitHub Impersonation Deploys Information Stealer - Arctic Wolf
Arctic Wolf’s SecOps team discovered a malicious GitHub page impersonating their brand to distribute an information-stealing malware called 'BoryptGrab Stealer.' The attack chain involved a trojanized…
- helpnetsecurity.com
GitHub’s new tool helps prevent costly open-source license violations - Help Net Security
GitHub introduced a new License Compliance feature in public preview for its Advanced Security customers, enabling automated scanning of open-source dependencies in pull requests to flag non-compliant…

- Featuregithub.blog
Kimi K2.7 Code is generally available in GitHub Copilot - The GitHub Blog
GitHub Copilot now offers Kimi K2.7 Code, an open-weight model, as a selectable option in the Copilot model picker. The model is available in Copilot Pro, Pro+, and Max plans, with rollout beginning i…
- Featuregithub.blog
Secret scanning public monitoring for enterprises - The GitHub Blog
GitHub introduced public monitoring for enterprises to detect leaked secrets in real time across all public content on github.com, attributing findings to the correct enterprise via verified domains a…
Track GitHub on autopilot
- · Weekly AI brief: narrative summary of what shipped, every Monday 9 AM
- · Email or Slack alerts, or chat with the archive in your dashboard
- · Add GitHub + up to 2 more competitors free, no credit card