// Alert

GitHub threat report

// GitHubMEDIUM

Researchers at Novee Security disclosed Cordyceps, a class of CI/CD vulnerabilities in GitHub Actions workflows affecting 300+ repositories. The attack exploits insecure workflow compositions using pull_request_target and workflow_run triggers that grant access to repository secrets and write tokens. Attackers can inject commands or code through pull requests to compromise projects from Microsoft, Google, Apache, Cloudflare, and the Python Software Foundation. The vulnerability is composition-based rather than file-level, allowing exploits to bypass traditional security scanners.

// Get alerts for GitHub