bleeping-computer · Crawled Jul 7, 2026
The GitHub Actions Attack Pattern Your CI Security Scanners Miss
Read original article ↗AI Summary
In June 2026, researchers at Novee Security identified a critical CI/CD vulnerability pattern named Cordyceps affecting widely used open-source projects, including those from Microsoft, Google, and Apache. The issue stems from the composition of GitHub Actions workflows that misuse privileged triggers like pull_request_target and workflow_run, enabling attackers to execute code in trusted contexts via pull requests. Despite passing all standard security checks, these pipelines allowed potential theft of long-lived credentials and persistent access to critical systems, highlighting a systemic gap in supply chain governance.
AI-extracted · verify before operational use
No entities or IoCs were extracted from this article.