Est. 2001·3,000+ placements · six offices · four regions
Cybersecurity Incidentcurated sourcedetected 2026-08-17 · confidence 95%

Last updated

GitHub: Cybersecurity Incident

GitHub experienced hours-long outage due to authentication failures

Source: ETtech (Economic Times)

The leadership read

A breach is a governance event before it is a technical one. For GitHub in the sector, the hiring consequence is rarely more engineers; it is senior accountability, security, risk and data governance reporting high enough to change decisions. Across Americas, watch whether the response is a hire or a contractor; that distinction says how the board has read it.

Market context: MitchelLake's Talent Market Index sits at 100.3 (Neutral), down 1 on the prior month; Americas hiring signal is running easing (-1.8pts).

GitHub: 4 signals in the last 90 days; 0.1% of MitchelLake's Americas signal flow; 4 tracked across 66 days.

Also at GitHub

More signals across Americas

Cybersecurity Incident · Americas

Vercel

CVE-2026-64650/64651: Vercel @ai-sdk/harness-codex/opencode vulnerabilities (CVSS 6.3 Medium) involved process-path validation bypass allowing malicious code in Linux sandbox to satisfy security checks. Fixes released July 20, 2026 in versions 1.0.29 and 1.0.28.

Cybersecurity Incident · Americas

Uber Freight

Hacking group Helix claimed responsibility for stealing internal files from Uber Freight's cloud infrastructure. Uber Freight confirmed unauthorised access to part of its systems but stated no impact on business operations.

Cybersecurity Incident · Americas

RingCentral

ShinyHunters extortion group breached RingCentral in July 2026, stealing personal information from 1.6 million customer accounts. Incident confirmed via Have I Been Pwned data breach notification service.

Cybersecurity Incident · Americas

Sentry

Publicly exposed Sentry Data Source Names (DSNs) were exploited as an attack vector via AI coding agents (Claude Code, Cursor) through Model Context Protocol integrations to achieve remote code execution and credential exfiltration. Attack succeeded 85% of the time across 100+ organizations; 2,388 organizations identified with publicly discoverable DSNs including 71 in Tranco top-1M and ~27% of Fortune 1000 via Cloudflare MCP alone. Sentry notified June 3, 2026; deployed content filter by June 12 but declined platform-level root-cause remediation.

Cybersecurity Incident · Americas

Bybit

Bybit suffered an alleged $1.5 billion ETH theft attributed to North Korea; a US court has frozen associated assets.

Cybersecurity Incident · Americas

Kaiser Permanente

Kaiser Permanente patient suffered wrongful hysterectomy due to pathology lab sample labeling error and misidentification, resulting in false cancer diagnosis and months of unnecessary treatment

Where this lands in our work

Weekly briefing

Track companies like GitHub — with our analysis

Anyone can set an alert for one company. We send a weekly read on the whole peer set — who's moving, and what it means for leadership. Pick what to follow:

Intelligence powered by Autonodal ↗

Nearby in the record