Tag: GitHub Actions

Researchers have uncovered Operation BlueDash, a phishing campaign that uses fake Microsoft Teams updates to deploy remote access tools and establish persistent access to Windows systems.
Viper Technology CEO Khushnood Aftab Shaikh met Sindh IT Company CEO Zainulabedin Shah to discuss potential collaboration opportunities focused on innovation and business growth.

Compromised GitHub Action Tags Used To Steal CI/CD Credentials In Software Supply Chain Attack

Threat actors compromised popular GitHub Actions workflows to exfiltrate CI/CD credentials through malicious code, raising concerns around software supply chain security and GitHub repository integrity.

Mini Shai Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI And Multiple Open Source Packages In Supply Chain Attack

A Mini Shai Hulud worm linked to TeamPCP has compromised npm and PyPI packages across TanStack, Mistral AI, Guardrails AI and others, deploying credential stealers, CI/CD exploits, and cross ecosystem propagation techniques.

Malicious Docker Images And VS Code Extensions Compromise Checkmarx Supply Chain

Security researchers report malicious Docker images and VS Code extensions tied to Checkmarx supply chain compromise, exposing developer credentials, cloud tokens, and CI/CD secrets through multi-stage malware and npm propagation.

OpenAI Revokes macOS App Certificate Following Malicious Axios Supply Chain Incident

OpenAI revokes its macOS app signing certificate after a malicious Axios supply chain attack, confirming no user data compromise while outlining security measures and broader ecosystem risks.

Cline CLI 2.3.0 Supply Chain Attack Led To Unauthorized OpenClaw Installation On Developer Systems

A compromised npm publish token was used to release Cline CLI version 2.3.0, triggering unauthorized installation of OpenClaw on developer systems during an eight hour supply chain attack window.

Recent articles

spot_img