Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Someone scold me if I'm wrong but this is really worrying. Threat actors with Github's internal code means a huge acceleration in vulnerability discovery for the one platform where everybody warehouses their code.

How is this not really, really bad?



This will not reassure you, but the reason it isn't necessarily really bad is because it's only incrementally worse than the really bad news came out last month:

Security researchers identified a series of exploitable vulnerabilities in github.com by using LLMs to review the compiled GitHub Enterprise Server binaries: https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-38...


It is really bad. But I think other Git providers also have weaknesses. Maybe it is just not a public knowledge or exploited.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: