Themata.AI
Themata.AI

Popular tags:

#developer-tools#ai-agents#llms#claude#ai-ethics#code-generation#ai-safety#openai#anthropic#discussion

AI is changing the world. Don't stay behind. Clear summaries, community insight, delivered without the noise. Subscribe to never miss a beat.

© 2026 Themata.AI • All Rights Reserved

Archive

|

Topics

|

Privacy

|

Cookies

|

Contact
githubcybersecurityai-toolsdeveloper-tools

What does GitHub's security team even do?

What does GitHub’s security team even do?

orchidfiles.com

July 26, 2026

4 min read

🔥🔥🔥🔥🔥

48/100

Summary

Thousands of repositories on GitHub are currently distributing malware, accessible through the standard search function without special knowledge. Despite having a substantial budget, a dedicated security team, and AI resources, GitHub has not resolved this issue over the past two years.

Key Takeaways

  • Thousands of repositories on GitHub are distributing malware, identifiable through standard search functions on the platform.
  • GitHub's security team deleted 10,000 malicious repositories identified by a script but did not implement further preventive measures.
  • The structure of the malicious repositories is similar, often containing headings with emojis and links to zip archives with Trojans.
  • A specific search query can be used to find repositories with links to zip archives containing malware, demonstrating a pattern that could be exploited for further identification.
Read original article

Community Sentiment

Negative

Positives

  • Improvements to GitHub Actions security show that pressure can lead to real change, though it feels like we need more pain first.
  • Some commenters see potential for package managers like PyPi to take a stand against insecure projects, which could force GitHub to step up its game.
  • The discussion hints at a need for stronger incentives for security teams, like tying executive bonuses to security performance.

Concerns

  • GitHub's response time to malicious repositories is often lackluster, pointing to a resource starvation issue rather than incompetence.
  • The sentiment that Microsoft may want to slowly kill the GitHub brand raises serious concerns about the platform's future and commitment to security.
  • Security is viewed as a cost-center, leading to a lack of investment until incidents start impacting revenue — this is a dangerous mindset.

Related Articles

I discovered a large-scale malware distribution campaign on GitHub

I found 10k GitHub repositories distributing Trojan malware

Jun 18, 2026

Glassworm Returns: Invisible Unicode Malware Found in 150+ GitHub Repositories

Glassworm Is Back: A New Wave of Invisible Unicode Attacks Hits Repositories

Mar 15, 2026

Microsoft’s stance on zero day exploits is a dumpster fire of their own making

Microsoft's stance on zero day exploits is a dumpster fire of their own making

May 28, 2026

Next chapter: Restructuring GitHub's bug bounty program

Restructuring GitHub's bug bounty program

Jul 23, 2026

Anatomy of a Failed (Nation-State?) Attack

Anatomy of a Failed (Nation-State?) Attack

Jun 27, 2026