GitHub Experiences Major Global Outage Affecting API, Actions, Copilot and Multiple Core Services
GitHub encountered a significant global outage on 17 August that affected almost every core function of the platform.
Home users, corporations, and Microsoft services all reported problems as the disruption spread across the web interface, API, Issues, Pull Requests, Actions, Webhooks, Pages, Git Operations, and Copilot.
At the height of the incident roughly 20 percent of requests to the website and API returned errors, while loads of repository archives and raw content saw failure rates near 50 percent.
Enterprise authentication systems including SAML and OIDC, as well as SCIM and Team Sync, were also impacted.
Codespaces continued to function normally throughout the event.
The first signs of degradation appeared around 13:40 UTC, after which problems sequentially emerged in API Requests, Actions, Webhooks, Issues, Pull Requests, Copilot, Pages, and Git operations.
GitHub engineers identified the faulty component and applied remediation steps. Latest updates indicate services are recovering, although error levels remain marginally above normal and the incident remains open.
Users simultaneously reported issues with other Microsoft ecosystem products such as Teams and Copilot. Experts suggested a possible connection to network problems at Amazon Web Services, but GitHub has not officially confirmed this hypothesis or disclosed the root cause.
Related articles
Prioritizing Account Protection: Moving From Job Titles to Real Business Risks
When budgets are limited, companies must decide whether to protect C-level executives first or focus on employees handling critical data such as accountants, database administrators, and developers. The article outlines four practical scenarios that determine protection priorities instead of relying on corporate hierarchy. These include perimeter defense through VPN access, safeguarding email and documents against phishing, addressing unique user cases like offline executive work, and managing contractor accounts with mandatory multi-factor authentication. A protection matrix maps assets such as commercial information, infrastructure access, and privileged accounts to specific threats and controls including 2FA, DLP systems, and PAM solutions. The piece also highlights three common mistakes, such as treating tool deployment as the finish line, underestimating pilot preparation, and attempting to secure everything simultaneously. It concludes with actionable first steps: inventory accounts, disable unused ones, enable two-factor authentication for high-risk users, and expand coverage gradually.
Russian Voice Traffic Surges 25-30% as Mobile Internet Usage Falls for First Time
In the first half of 2026, voice traffic in Russian mobile networks grew by 25-30 percent while mobile internet consumption declined 10-12 percent for the first time. Home broadband traffic rose 18-20 percent as users shifted conversations to traditional voice calls and moved video, AI services, and other data-heavy applications to fixed Wi-Fi connections. Experts attribute the changes primarily to mobile internet restrictions and difficulties accessing foreign messengers, prompting a return to basic phone functionality. Additional load on wired networks comes from IoT devices including surveillance cameras, sensors, and smart watches. In May, traffic generated by AI bots exceeded the volume of data created by human users for the first time. Analysts forecast that by the end of 2026 mobile internet traffic will drop another 5-10 percent, while fixed broadband will grow 15-20 percent and voice call volumes will increase 10-15 percent.
Incident Reconstruction Fails When Logs Lack Time Zone Offsets and Proper Synchronization
Reconstructing security incidents from multiple log sources often collapses when timestamps lack time zone information or consistent synchronization. Events from web servers, load balancers, applications, and mail gateways can appear in physically impossible order, such as responses preceding requests or sessions closing before they open. The root causes include clock drift without NTP, mismatched reference points like UTC versus local time, and timestamps recorded at message processing rather than event occurrence. Classic BSD syslog (RFC 3164) omits both year and offset, forcing investigators to consult potentially unavailable source systems. Modern RFC 5424 provides full timestamps with offsets, making normalization possible without external context. Organizations must enforce offset-inclusive formats at ingestion, monitor actual synchronization status rather than service uptime, and document external sources whose timestamps cannot be controlled.
HTTP Methods Explained: GET, POST, PUT, PATCH, DELETE and the New QUERY Standard
HTTP methods define the actions a client requests from a server regarding a resource. The core semantics are outlined in RFC 9110, with extensions for specialized protocols. A new standardized method called QUERY was introduced in June 2026 via RFC 10008 to handle complex queries that include a request body while remaining safe and idempotent. The article details safe and idempotent properties, compares each method including GET, HEAD, POST, PUT, PATCH, DELETE, OPTIONS, TRACE, CONNECT, and QUERY, and explains their correct usage to avoid breaking caches, proxies, and infrastructure expectations. It also covers WebDAV extensions and other registered methods in the IANA registry.