Menu

Post image 1
Post image 2
Post image 3
1 / 3
0

Investigation update: GitHub Enterprise Server signing key rotation

The GitHub Blog·Natalie Guevara·4 days ago
#ozAVZUvl
Reading 0:00
15s threshold

May 26, 2026 : GitHub recently detected a cyber-attack and immediately activated our response process to investigate, disrupt malicious activity, mitigate the attack, and deny the threat actor further access. It’s important to note that this investigation is still ongoing, and we will continue to provide details as appropriate. Given the reality of threat actors and the advent of AI technologies, we need to do all we can to protect our customers. Considering the repositories that have been attacked and an abundance of caution, we are rotating keys, including the GitHub Enterprise Server signing key. This key is used to sign binaries for GitHub Enterprise Server to validate GitHub as the source during a manually initiated update process. All binaries hosted by GitHub are valid. GitHub Enterprise Server customers need to take immediate action as described below. No action is required for GitHub Enterprise Cloud.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More