Hacker News new | ask | show | jobs
by prodigycorp 22 days ago
Someone scold me if I'm wrong but this is really worrying. Threat actors with Github's internal code means a huge acceleration in vulnerability discovery for the one platform where everybody warehouses their code.

How is this not really, really bad?

2 comments

This will not reassure you, but the reason it isn't necessarily really bad is because it's only incrementally worse than the really bad news came out last month:

Security researchers identified a series of exploitable vulnerabilities in github.com by using LLMs to review the compiled GitHub Enterprise Server binaries: https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-38...

It is really bad. But I think other Git providers also have weaknesses. Maybe it is just not a public knowledge or exploited.