๐จData Breach Alert โผ๏ธ
๐ง๐ฒ๐ฎ๐บ๐ฃ๐๐ฃ ๐๐น๐ฎ๐ถ๐บ๐ ๐ฆ๐ฎ๐น๐ฒ ๐ผ๐ณ ๐๐ถ๐๐๐๐ฏ ๐๐ป๐๐ฒ๐ฟ๐ป๐ฎ๐น ๐ฆ๐ผ๐๐ฟ๐ฐ๐ฒ ๐๐ผ๐ฑ๐ฒ
TeamPCP hacking group claimed the compromise and sale of GitHub internal data, allegedly including around 4,000 private repositories containing source code related to GitHubโs main platform and internal organizations.
Threat actor: TeamPCP
Sector: ICT
Data exposure (claimed): Approximately 4,000 private repositories
Data type: Source code
Observed: May 19, 2026
Status: Pending verification
ESIXยฉ: 7.96
Full details and impact assessment on https://t.co/eB7qgxKFAa
We are investigating unauthorized access to GitHubโs internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHubโs internal repositories (such as our customersโ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
To be secure in 2026 you have to shut down your bug bounty program on HackerOne.
Lovable got hacked because HackerOne's incompetent triage team closed multiple valid vulnerability reports starting February 22, 2026 as "intended behavior."
Poorly trained monkeys. Zero escalation to Lovable's security team. AI bots auto-closing critical findings.
The result? Public project chat history and source code were exposed for MONTHS until a researcher was forced to go public.
Two companies. Same platform. Same failure. Same lies.
ClickUp. Lovable. Both breached because HackerOne buried critical reports while collecting your bounty fees.
HackerOne is NOT a security partner. They are a liability.
They close real vulnerabilities. They protect their own metrics over your data. They let researchers get attacked while they stay silent.
Stop paying HackerOne to get hacked.
https://t.co/Sb1AoiOG6L