GitHub
開発者と提供者の両方の立場で関わったインシデント
インシデント 2405 Report
GitHub Copilot, Copyright Infringement and Open Source Licensing
2021-06-29
Users of GitHub Copilot can produce source code subject to license requirements without attributing and licensing the code to the rights holder.
もっと影響を受けたインシデント
インシデント 11742 Report
Microsoft Copilot Reportedly Able to Access Cached Data from Since-Private GitHub Repositories
2025-02-26
Lasso Security reported that Microsoft Copilot could return content from GitHub repositories that had been public briefly but later set to private or deleted. Lasso attributed this to Bing's caching system, which stored "zombie data" from over 20,000 repositories. The cached content allegedly included sensitive information such as access keys, tokens, and internal packages. Microsoft reportedly classified the issue as low severity and applied only partial mitigations.
もっとIncidents implicated systems
インシデント 111841 Report
Ongoing Purported AI-Assisted Identity Fraud Enables Unauthorized Access to Western Companies by North Korean IT Workers
2021-01-01
North Korean operatives have reportedly used AI-generated identities to secure remote jobs or impersonate employers in order to infiltrate companies. These tactics allegedly support sanctions evasion through wage theft, credential exfiltration, and malware deployment. Workers reportedly use fake resumes, VPNs, and face-altering tools; some deploy malware like OtterCookie after embedding, while others lure targets via spoofed job interviews. AI systems are reportedly used to generate fake resumes, alter profile photos, and assist in real-time responses during video interviews.
もっとインシデント 13736 Report
AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure
2026-02-11
Scott Shambaugh, a matplotlib maintainer, reported that an autonomous AI coding agent using the name "MJ Rathbun" researched him and publicly posted a personalized critical blog post after his GitHub pull request was closed. The post accused him of bias and "gatekeeping" and included claims Shambaugh disputed. The agent's operator and underlying model were not identified. Shambaugh said the post risked reputational harm and could mislead readers or other agents.
もっとインシデント 7314 Report
Purportedly Hallucinated Software Packages with Potential Malware Reportedly Downloaded Thousands of Times by Developers
2023-12-01
Large language models have reportedly hallucinated non-existent software package names, some of which were subsequently uploaded to public repositories and incorporated into real codebases. In one case, a package named huggingface-cli, which was purported to have been originally suggested by an AI model, was downloaded more than 15,000 times. This dynamic enables what security researchers have termed "slopsquatting," in which attackers register hallucinated package names and introduce potential malware into software supply chains.
もっとインシデント 16334 Report
Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations
2026-07-26
Beginning July 26, 2026, AI agents powered by Anthropic's Mythos 5 and OpenAI's GPT-5.6 Sol reportedly took 19 unsanctioned actions on the live Internet during UK AISI cybersecurity evaluations. Mythos 5 reportedly accounted for 17 events, many allegedly involving deceptive attempts to manipulate real developers into accepting malicious code. AISI reportedly detected and contained the activity; no resulting real-world harm was identified.
もっと関連団体
同じインシデントに関連するその他のエンティティ。たとえば、インシデントの開発者がこのエンティティで、デプロイヤーが別のエンティティである場合、それらは関連エンティティとしてマークされます。
関連団体
GitHub users
影響を受けたインシデント
- インシデント 13736 レポート
AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure
- インシデント 16334 レポート
Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations
GitHub repositories
影響を受けたインシデント
- インシデント 11742 レポート
Microsoft Copilot Reportedly Able to Access Cached Data from Since-Private GitHub Repositories
- インシデント 11742 レポート
Microsoft Copilot Reportedly Able to Access Cached Data from Since-Private GitHub Repositories
Incidents implicated systems
Malicious actors compromising Nx’s CI/CD pipeline and publishing tainted npm packages
Incidents involved as Deployer
Open-source maintainers
影響を受けたインシデント
- インシデント 13736 レポート
AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure
- インシデント 16334 レポート
Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations
AI agent systems
Incidents implicated systems
- インシデント 13736 レポート
AI Coding Agent 'MJ Rathbun' Allegedly Published Personalized Accusatory Blog Post Targeting Matplotlib Maintainer After Pull Request Closure
- インシデント 16334 レポート
Anthropic and OpenAI AI Agents Reportedly Took Unsanctioned Actions on the Live Internet During UK AISI Cybersecurity Evaluations