Tag
GitHub
Every GitHub story we've curated in Bowl of Data, newest issue first — part of our weekly digest across AI, security, blockchain, and engineering.
Week 30 · 2026
Read the issue →-
Block built a Slack for AI agents — and gave each one its own passport
Block has introduced Buzz, a decentralized Slack alternative that integrates AI agents as first-class participants using cryptographic identities. Built on the Nostr protocol, it allows for secure, verifiable collaboration between humans and various autonomous AI models.
Week 29 · 2026
Read the issue →-
Lessons Learned from CISA’s Recent GitHub Leak
CISA recently released a postmortem regarding a six-month exposure of internal credentials on GitHub caused by a contractor's error. The report details failures in incident notification response and the complexities of rotating secrets within large-scale federal environments.
Week 28 · 2026
Read the issue →-
Lessons from CISA’s Cyber Incident
CISA released an after-action report regarding a credential leak caused by a contractor's use of a personal GitHub repository. The agency successfully mitigated the exposure without loss of mission data and is implementing stricter development environment guardrails.
Week 26 · 2026
Read the issue →-
Anthropic gives @Claude a permanent seat in your Slack channels
Anthropic's new Claude Tag feature transforms Claude from a reactive chatbot into an autonomous agent living within Slack channels. It utilizes a unique 'agent identity' model to allow for secure, multi-user collaboration on long-running enterprise tasks.
Week 24 · 2026
Read the issue →-
For the 2nd time in weeks, Microsoft packages laced with credential stealer
Threat actors have successfully compromised dozens of Microsoft-owned repositories to deploy the Miasma malware via supply-chain attacks. The malware is designed to steal cloud credentials and spread laterally through developer environments by exploiting AI coding agents.
Week 23 · 2026
Read the issue →-
Red Hat npm packages compromised to steal developer credentials
More than 30 Red Hat npm packages were compromised in a supply-chain attack using the Miasma malware to steal developer credentials. The attack was executed via a compromised GitHub account and targeted various cloud and infrastructure secrets.
Week 21 · 2026
Read the issue →-
America's top cyber-defense agency left a GitHub repo open with with passwords, keys, tokens – and incredibly obvious filenames
The US Cybersecurity and Infrastructure Security Agency (CISA) was found to have left a massive GitHub repository containing plain-text credentials and infrastructure secrets public for six months. The leak, discovered by a GitGuardian researcher, exposed access to critical systems like AWS, Azure, and Kubernetes, highlighting severe internal security lapses.
-
GitHub hit by a compromised VSCode extension
GitHub reported detecting and containing a security breach concerning unauthorized access to its internal repositories. The compromise originated from a poisoned VS Code extension found on an employee's device, prompting immediate incident response measures.
Week 20 · 2026
Read the issue →-
Official CheckMarx Jenkins package compromised with infostealer
The TeamPCP hacker group has compromised the Checkmarx Jenkins AST plugin by leveraging credentials stolen from a previous Trivy scanner breach. This supply-chain attack allows for the delivery of credential-stealing malware to developer environments.
Week 19 · 2026
Read the issue →-
Bleeding Llama: Critical Unauthenticated Memory Leak in Ollama (CVE-2026–7482)
A critical vulnerability in Ollama allows unauthenticated attackers to trigger an out-of-bounds heap read via malicious GGUF files. This exploit can expose sensitive information like user messages and system prompts by leaking them into newly created model files.
Free weekly digest
Get next Saturday’s issue in your inbox
The week’s most relevant AI, security, blockchain, and engineering stories — curated, summarised, and reviewed by humans. No spam, unsubscribe anytime.
Subscribe — it’s free