GitHub is investigating unauthorized access to its internal repositories after TeamPCP claimed to have accessed approximately 4,000 repositories containing private code. The claim follows the group's history of supply chain attacks on GitHub, PyPI, NPM, Docker and other platforms including the recent Trivy and LiteLLM compromises.

As always this is not a ransom, We do not care about extorting Github, 1 buyer and we shred the data on our end, it looks like our retirement is soon so if no buyer is found we will leak it free.
The Trivy breach also affected the LiteLLM open-source Python library in an attack that infected tens of thousands of devices with its "TeamPCP Cloud Stealer" information-stealing malware.
Expert Take: Cloud administrators should audit CI/CD credentials and scanner tool integrity across their supply chains to limit exposure to repeated TeamPCP-style attacks.
Tap a lens to see what this story means for you.
Reader-supported · Daily Brief
Daily brief at 7 AM ET. Top tech stories, every morning. Sourced and fact-checked.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
CISA warned that hackers are actively exploiting a recently patched high-severity flaw in SolarWinds Serv-U software to crash servers and added it to its Known Exploited Vulnerabilities Catalog. The agency ordered federal agencies to patch by June 19 and urged all organizations to mitigate the ongoing attacks immediately.
S&P Dow Jones Indices refused to waive seasoning, profitability, or public float rules for SpaceX's IPO, blocking accelerated S&P 500 entry that could have unlocked billions in passive funds. The same barriers now apply to expected IPOs from OpenAI and Anthropic, limiting exposure of retirement assets to unprofitable AI bets.
New York lawmakers approved a one-year moratorium on new large data centers, the first such statewide measure if signed by Governor Hochul. The pause aims to study environmental and energy impacts amid growing AI-driven demand.