GitHub App keys can still enable takeovers long after they are forgotten
GitHub allows organizations to install GitHub Apps that automate and extend certain functionality on the platform and have access to selected repositories and permissions. But the private keys these applications use to authenticate themselves can remain valid for years unless manually revoked. If leaked, those keys can…
Short extract only — this publisher licenses its text. Read the full release at the source.
More from CSO Online
- F5 fixes actively exploited zero-day flaw in BIG-IP APM
- Okta bets on identity to control AI agents, but is identity enough?
- AI malware just removed the human from the attack loop
The rest of this wire is for subscribers
Every release from this source, the moment it crosses — plus 80+ other newswires, saved searches and instant alerts.
7 days, no card required.
Read releases like this the second they cross the wire.
1,400+ feeds — live on PPN World right now. Every release from this source, the moment it crosses — plus 80+ other newswires, saved searches and instant alerts.
Start the free trial →Your announcement next? Distribute your press release to the global wires with PPN Source — and track its pickup live here.
PPN Source →