Python-Community-News / Topics

Submit topics to PCN to be covered on the Show
MIT License
2 stars 1 forks source link

Thousands of GitHub repositories deliver fake PoC exploits with malware #38

Closed kjaymiller closed 2 years ago

kjaymiller commented 2 years ago

URL

https://www.bleepingcomputer.com/news/security/thousands-of-github-repositories-deliver-fake-poc-exploits-with-malware/

When was this post released

23 October 2022

Summary

Researchers at the Leiden Institute of Advanced Computer Science found thousands of repositories on GitHub that offer fake proof-of-concept (PoC) exploits for various vulnerabilities, some of them including malware.

According to the technical paper from the researchers at Leiden Institute of Advanced Computer Science, the possibility of getting infected with malware instead of obtaining a PoC could be as high as 10.3%, excluding proven fakes and prankware.

Soufian believes that all testers should follow these three steps:

The researchers have reported all the malicious repositories they discovered to GitHub, but it will take some time until all of them are reviewed and removed, so many still remain available to the public.

Code of Conduct