GetChain News
中简 中繁 EN
GetChain News
Toggle sidebar

“Cordyceps” CI/CD Supply Chain Vulnerability Pattern Exposed, Affecting Code Repositories of Microsoft, Google, and Others

Source: novee.security Event types: Security/Hacker
Cybersecurity firm Novee, in its latest research, revealed a CI/CD supply chain vulnerability pattern dubbed “Cordyceps,” primarily involving command injection, authentication logic flaws, artifact poisoning, and privilege escalation within GitHub Actions workflows. According to the report, unauthenticated users can exploit these vulnerabilities under specific conditions to hijack workflows, steal credentials, or gain control of code repositories.

Related investors

Related projects