Tag: GitHub Actions

SolarWinds releases security updates for Access Rights Manager to fix a high severity vulnerability that could enable unauthenticated remote code execution.
Awan Distribution conducts Huawei eKit Partner Enablement Session covering IP Networks and IT Storage solutions to enhance partner knowledge and opportunities.

Claude Code GitHub Action Flaw Exposed Public Repositories To Repository Hijacking Risks

A security flaw in Anthropic’s Claude Code GitHub Action allowed attackers to potentially hijack public repositories through a single malicious GitHub issue.

Compromised GitHub Action Tags Used To Steal CI/CD Credentials In Software Supply Chain Attack

Threat actors compromised popular GitHub Actions workflows to exfiltrate CI/CD credentials through malicious code, raising concerns around software supply chain security and GitHub repository integrity.

Mini Shai Hulud Worm Compromises TanStack, Mistral AI, Guardrails AI And Multiple Open Source Packages In Supply Chain Attack

A Mini Shai Hulud worm linked to TeamPCP has compromised npm and PyPI packages across TanStack, Mistral AI, Guardrails AI and others, deploying credential stealers, CI/CD exploits, and cross ecosystem propagation techniques.

Malicious Docker Images And VS Code Extensions Compromise Checkmarx Supply Chain

Security researchers report malicious Docker images and VS Code extensions tied to Checkmarx supply chain compromise, exposing developer credentials, cloud tokens, and CI/CD secrets through multi-stage malware and npm propagation.

OpenAI Revokes macOS App Certificate Following Malicious Axios Supply Chain Incident

OpenAI revokes its macOS app signing certificate after a malicious Axios supply chain attack, confirming no user data compromise while outlining security measures and broader ecosystem risks.

Cline CLI 2.3.0 Supply Chain Attack Led To Unauthorized OpenClaw Installation On Developer Systems

A compromised npm publish token was used to release Cline CLI version 2.3.0, triggering unauthorized installation of OpenClaw on developer systems during an eight hour supply chain attack window.

Recent articles

spot_img