supply-chain
'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows
High
Summary
A new vulnerability, dubbed "Cordyceps," is targeting CI/CD workflows across several open-source projects, including Azure Sentinel, Doris, Workers SDK, and Black. Attackers can exploit weak automated processes within these workflows to gain unauthorized access, execute malicious code, and potentially compromise the entire software supply chain. The issue stems from overly permissive access granted to pull requests, allowing attackers to steal credentials, inject commands, and manipulate CI/CD configurations.
Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data
