Skip to content
Threat Feed

Product

GitHub Enterprise

12 briefs RSS
high advisory

GitHub Enterprise Branch Ruleset Deletion

Detection of GitHub Enterprise branch ruleset deletion events in audit logs, potentially indicating attempts to bypass security controls and compromise code integrity.

GitHub Enterprise github branch-ruleset defense-evasion supply-chain
2r 2t
medium advisory

GitHub Enterprise Audit Log Streaming Paused

Detection of a user pausing audit log event streaming in GitHub Enterprise, potentially indicating an attempt to evade detection by disabling the audit trail.

GitHub Enterprise +3 github audit-log defense-evasion
2r 2t
high advisory

GitHub Enterprise Organization Removal

Detection of a user removing an organization from GitHub Enterprise, potentially indicating account compromise, insider threats, or malicious attempts to disrupt business operations by deleting critical business resources.

GitHub Enterprise github cloud impact
2r 2t
high advisory

GitHub Enterprise Self-Hosted Runner Creation

Anomalous creation of self-hosted runners in GitHub Enterprise indicates potential attacker activity to execute malicious code, access sensitive data, or pivot to other systems via compromised runners.

GitHub Enterprise github supply-chain self-hosted-runner defense-evasion initial-access
2r 2t
high advisory

GitHub Enterprise IP Allow List Disabled

An IP allow list was disabled in GitHub Enterprise, potentially allowing unauthorized access to sensitive code repositories and GitHub Enterprise resources from untrusted networks.

GitHub Enterprise github cloud ip-allow-list defense-evasion
2r 2t
high advisory

GitHub Enterprise Classic Branch Protection Disabled

An attacker disables classic branch protection rules in GitHub Enterprise, potentially to bypass code review and security controls leading to code tampering, vulnerability introduction, or supply chain compromise.

GitHub Enterprise github branch-protection defense-evasion
2r 2t
high advisory

GitHub Enterprise Audit Log Streaming Paused

A user pausing the audit log event stream in GitHub Enterprise, potentially indicating an attempt to evade detection by disabling audit trails.

GitHub Enterprise github audit-log defense-evasion cloud
2r 2t
high advisory

GitHub Enterprise Audit Log Streaming Modification

Detection of modifications or disabling of audit log event streaming in GitHub Enterprise, potentially indicating an attacker attempting to evade detection by tampering with the audit trail.

GitHub Enterprise github audit-log defense-evasion cloud
2r 3t
high advisory

GitHub Enterprise Audit Log Streaming Disabled

A user disabling audit log event streaming in GitHub Enterprise could indicate an attacker attempting to prevent their malicious activities from being logged and detected.

GitHub Enterprise github audit-logs defense-evasion cloud
2r 2t
high advisory

GitHub Enterprise 2FA Requirement Disabled

The disabling of two-factor authentication (2FA) in GitHub Enterprise, detected via audit logs, weakens account security and increases the risk of account takeover and supply chain compromise.

GitHub Enterprise +3 github 2fa defense-evasion
2r 1t
high advisory

GitHub Enterprise Dependabot Disablement

An attacker disables Dependabot in a GitHub repository to prevent automatic vulnerability detection, potentially leading to exploitation of unpatched dependencies and supply chain compromise.

GitHub Enterprise github dependabot supply-chain defense-evasion
3r 2t
high advisory

GitHub Enterprise 2FA Requirement Disabled

Detection of two-factor authentication (2FA) being disabled in GitHub Enterprise, potentially weakening account security and facilitating unauthorized access by threat actors.

GitHub Enterprise github 2fa defense-evasion initial-access
2r 2t