Fake files on Github might be malware – even from “Microsoft”


by MSPoweruser

MSPoweruser— Security researchers have identified a vulnerability in GitHub’s comment file upload system that malicious actors are exploiting to spread malware. Here’s how it works: When a user uploads a file to a GitHub comment (even if the comment itself is never posted), a download link is automatically generated. This link includes the name of the repository and its owner, […]

Neowin—GitHub abused to host malware and create download links seemingly affiliated with Microsoft. File upload logic in GitHub's comments allows hackers to host malware on the service and abuse trusted developers and companies, such as Microsoft, to create legitimate-looking URLs.

VG247—Yes, it might even give you a reason to actually drive the Williams. No matter whether you're a big car nerd who loves playing around with setups, or are just hopping in for a quick race against your mates, how the cars feel to drive in an F1 game is pretty key. After all, what you're hoping for in both cases is to get a taste of the same sensation the likes of Max Verstappen or Lewis Hamilton enjoys as they sweep through turns and blast down straights.We recently had a chance to see what EA Sports F1 24, the latest game in Codematers' long-running series, has...

MSPoweruser—Microsoft-backed OpenAI might unveil its search engine on May 9th. OpenAI is hinting at a major announcement that could shake up the search engine landscape. Rumors suggest they might unveil a brand new search engine as early as May 9th, 2024. If this happens to be true, this could be a trump card move by Microsoft, which backs OpenAI, after leaked mail shows that Microsoft […]