CriticalSecurity & Privacy
Microsoft disabled 70+ of its repos on GitHub, including Azure-related tools like azure-functions-host, after hackers added credential-stealing malware to them (Zack Whittaker/TechCrunch)
Microsoft disabled over 70 GitHub repositories, including critical Azure infrastructure tools, after discovering attackers injected credential-stealing malware, exposing a significant supply chain vulnerability that could impact any organization consuming these open source dependencies. This incident highlights the escalating risk of compromised development tools and underscores the need for IT leaders to reassess their open source software governance and dependency management practices. Organizations relying on affected Azure tools face potential credential exposure and must immediately audit their deployments and update to patched versions.
