INTEL_REPORT
The Hacker News · published 7/8/2026, 11:51:24 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
GitHub 'Verified' Commits Can Be Rewritten Into New Hashes Without Breaking Signatures New research shows that a signed Git commit's hash is not the one-of-a-kind name that much of the software world assumes it to be. Given any signed commit, someone without the signing key can mint a second commit with the same files, author, and date, and a valid signature, GitHub still stamps "Verified." Everything a reviewer would check matches. The commit's hash does not. That matters …
https://thehackernews.com/2026/07/github-verified-commits-can-be.html
sha256:9288166b961201145f380a27bad7ae74927f86ba568cc38aa5366a6a70d96874
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.