Advertisement
ChainDrop npm Worm: Self-Propagating Software Supply Chain Threat
Analyze the ChainDrop self-propagating npm worm infecting major packages, harvesting credentials from memory, and compromising CI/CD pipelines.
Cloudflare's Flue Automates Open Source Issue Triage
Cloudflare details how its Flue framework automates Astro's GitHub issue triage, significantly reducing open issues and improving maintainer efficiency.
Defending Against the 1,444% Surge in Open Source Supply Chain Attacks
GTIG reports a massive 1,444% spike in open source repository compromises. Learn how to mitigate threats from actors like UNC6780 and MIDNIGHT NEPTUNE.
GitHub Actions Runners Weaponized to Attack cPanel and WHM Servers
Attackers are leveraging GitHub Actions runners and compromised Packagist packages to launch distributed attacks against cPanel and WHM server instances.
GitHub Actions Attack Patterns Evade CI Security Scanners
Learn how sophisticated GitHub Actions attack patterns bypass traditional CI security scanners, exposing CI/CD pipelines to supply chain risks.
Cordyceps: Defending Against Malicious Pull Requests in CI/CD
The Cordyceps campaign highlights critical CI/CD vulnerabilities in GitHub Actions, targeting high-profile projects like Apache Doris and Cloudflare Workers SDK.
Advertisement
Anthropic Claude Code GitHub Action Flaw Enables Repo Hijacking
A critical flaw in Anthropic's Claude Code GitHub Action allowed attackers to hijack public repositories using malicious issues, posing supply chain risks.
Megalodon Supply Chain Attack Infects 5,500+ GitHub Repositories
Attackers used automated commits to inject malicious GitHub Actions workflows into 5,500+ repositories, targeting CI/CD secrets and sensitive tokens.
Megalodon Campaign: 5,561 GitHub Repos Hit by Malicious Workflows
Automated Megalodon attack pushes 5,718 malicious commits to GitHub repositories to exfiltrate secrets via GitHub Actions workflows.
Grafana Breach After TanStack Attack: Token Rotation Failure
Grafana suffered a data breach due to a GitHub workflow token not rotated after the TanStack npm supply-chain attack, impacting user data. Learn the details.
GitHub Actions Supply Chain Attack: actions-cool/issues-helper
Analysis of the actions-cool/issues-helper supply chain attack where tags were redirected to steal credentials. Learn how to detect and mitigate this threat.
Gemini CLI Critical RCE Fix: Patching the @google/gemini-cli Flaw
Google patches a CVSS 10.0 flaw in Gemini CLI tools that allowed unprivileged attackers to execute commands in CI/CD environments via malicious configurations.
OpenAI Revokes macOS App Certificate Following Supply Chain Attack
OpenAI revokes its macOS app signing certificate after a GitHub Actions workflow downloaded a malicious Axios library version during a supply chain incident.
Axios NPM Supply Chain Attack Bypasses GitHub Actions CI/CD
A sophisticated supply chain attack targeted the Axios NPM package, leveraging a compromised token to bypass GitHub Actions CI/CD and deploy malicious versions.
TeamPCP Supply Chain Attacks Target Docker Hub, PyPI, and VS Code
TeamPCP expands supply chain attack tactics from GitHub Actions to Docker Hub, PyPI, and VS Code extensions, collaborating with the Lapsus$ hacking group.
Trivy Supply Chain Attack: TeamPCP Pushes Infostealer via GitHub
Threat actor TeamPCP compromised the Trivy-action repository to distribute infostealer malware through GitHub Actions, targeting CI/CD pipelines and secrets.
75 Trivy-Action GitHub Tags Hijacked in Supply Chain Attack
Attackers hijacked 75 tags in Aqua Security's Trivy GitHub Actions to exfiltrate CI/CD secrets, marking the second major breach in a single month.
Tag Poisoning Compromises Xygeni GitHub Action, C2 Implant Active
Attackers compromised the `xygeni/xygeni-action` GitHub Action using tag poisoning, deploying a C2 implant for up to a week. Users must verify integrity and review logs.