supply-chain Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks A new vulnerability, dubbed 'Cordyceps,' has been discovered in CI/CD workflows, allowing unauthorized access and control over hundreds of GitHub repositories across major tech companies. The flaw stems from overly permissive pull request configurations, enabling attackers to execute malicious code and steal credential… The Hacker News · Jun 24, 2026 Critical cicdsupply chaingithub
supply-chain 'Cordyceps': Mushrooming Malicious Pull Requests Threaten Developer Workflows A new vulnerability, dubbed "Cordyceps," is targeting CI/CD workflows across several open-source projects, including Azure Sentinel, Doris, Workers SDK, and Black. Attackers can exploit weak automated processes within th… Dark Reading · Jun 23, 2026 High cicdsupply chainpull requests