news.mlab.sh
Back to the feed
supply-chain

Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks

Critical
Image: The Hacker News
Summary

A new vulnerability, dubbed 'Cordyceps,' has been discovered in CI/CD workflows, allowing unauthorized access and control over hundreds of GitHub repositories across major tech companies. The flaw stems from overly permissive pull request configurations, enabling attackers to execute malicious code and steal credentials. This represents a significant supply-chain risk with potentially severe consequences for affected organizations.

Read the full article at The Hacker News

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.