Top
GitHub attacker launched massive login campaign using stolen passwords

GitHub attacker launched massive login campaign using stolen passwords

June 17, 2016

Category:

On June 14, someone using what appears to have been a list of e-mail addresses and passwords obtained from the breach of “other online services” made a massive number of login attempts to GitHub’s repository service. A review of logins by GitHub’s administrators found that the attacker had gained access to a number of accounts, according to a blog post by Shawn Davenport, Vice President of Security at GitHub.

It’s not clear what the source of the e-mail/password combinations was, but there are certainly plenty of them out there right now—the recent bounty of “megabreaches,” consisting of aged passwords from MySpace, Tumblr, LinkedIn and the dating site Fling, totaled more than 642 million accounts in all.

Read More on ArsTechnica