How Stolen OAuth Tokens Let Attackers Access Private GitHub Repositories
GitHub revealed that attackers exploited stolen OAuth tokens from third‑party services like Heroku and Travis‑CI to download private repository data, prompting a rapid revocation of tokens and ongoing investigation into the breach.
