GitHub’s Bug Bounty Program is evolving to prioritize high-quality, high-impact research.
Learn about our next chapter: new VIP program, restructured public bounties, and updated signal requirements, all designed to build stronger researcher partnerships.
GitHub had 14,000+ internal repositories, but fewer than half had a clear owner.
In under 45 days, we validated ownership for every active repo and archived 8,000 that were no longer used.
Here’s how we made ownership durable, and how you can too. 💡
GitLab has apparently taken down the Nightmare-Eclipse account just days after the researcher moved there following the GitHub ban.
The drama started after Nightmare-Eclipse released several Windows exploits and Defender bypass tools, including BlueHammer, RedSun, and UnDefend. GitHub removed the account earlier this week over concerns that the tools could be misused and weaponized.
Security company Huntress says some of the tools have already been seen in real-world intrusion cases, showing how quickly proof-of-concept research can end up being used in actual attacks.
GitHub has reportedly been hacked.
A group called TeamPCP claims it gained unauthorized access to GitHub’s internal systems and stole data from around 4,000 private and internal repositories, including source code and company files.
They are now trying to sell this stolen data for more than $50,000 on underground forums and have said they will release it for free if no one buys it.
GitHub is investigating the unauthorized access and says it has found no evidence so far that customer data, organizations, or customer repositories were affected.
GitBook hosts 30,000 sites on a single Vercel deployment, and over 40% of their traffic is from AI agents.
How they solve multi-tenant caching at scale ↓