🚨 AI-Powered GitHub Attack Steals Secrets from Open Source Projects 🚨
A sophisticated AI-assisted supply chain attack called "PRT-scan" has targeted hundreds of GitHub repositories using fake pull requests to exfiltrate developer credentials and secrets. The campaign, which began on March 11, 2026, leverages automated AI to rapidly identify and exploit GitHub Actions misconfigurations across open source projects. Threat actors created multiple disposable accounts to submit over 256 malicious pu...