CrowdSec Confirms Source Code Stolen in Supply Chain Attack

https://www.securityweek.com/wp-content/uploads/2025/12/Code-3rd-Party-Risk.jpg

French cybersecurity firm CrowdSec has confirmed that approximately 300 private and public repositories were compromised and source code was stolen from them.

The company provides open source, crowdsourced threat intelligence, including a lightweight security engine to detect and block attacks targeting servers, networks, and applications.

Last week, the French outfit learned that source code had been stolen from its GitHub repositories in May 2026.

CrowdSec has confirmed the report, noting that both private and public code was exfiltrated, and that roughly 300 repositories were affected, including approximately 170 private ones.

“The private part contains the source code for our SaaS console, some AWS Cloud routines, some connectors, and automations,” the company said.

According to CrowdSec, no credentials or other types of data related to its customers were leaked, and the impact is limited to its own organization.

Advertisement. Scroll to continue reading.

“Our team quickly hunted for any token, credential,...

Copyright of this story solely belongs to www.securityweek.com. To see the full text click HERE

Read more

https://cdn.mos.cms.futurecdn.net/ghkY9CqeiheUvFSMCkRtNK-2560-80.jpg

Samsung and LG vow to remove 'botnet' apps from their smart TV app stores that turned sets into an AI scraping machines — but the shocking claim that over 40% of webOS apps had botnet code raises the question of how things ever got this bad

* Malware botnets route traffic through the internet connection on many smart TVs * Roku, Fire TV, Tizen and webOS all affected * Some manufacturers are removing affected apps LG, Samsung, Roku and Fire TV televisions and devices may have been part of a malicious "botnet" — and millions of TVs could