Security News > 2025 > March > Critical GitHub Attack

This is serious: A sophisticated cascading supply chain attack has compromised multiple GitHub Actions, exposing critical CI/CD secrets across tens of thousands of repositories. The attack, which originally targeted the widely used “tj-actions/changed-files” utility, is now believed to have originated from an earlier breach of the “reviewdog/action-setup@v1” GitHub Action, according to a report. […] CISA confirmed the vulnerability has been patched in version 46.0.1. Given that the utility is used by more than 23,000 GitHub repositories, the scale of potential impact has raised significant alarm throughout the developer community...
News URL
https://www.schneier.com/blog/archives/2025/03/critical-github-attack.html
Related news
- SAP fixes critical Netweaver flaw exploited in attacks (source)
- Fortinet fixes critical zero-day exploited in FortiVoice attacks (source)
- ‘Deliberate attack’ deletes shopping app’s AWS and GitHub resources (source)
- New PathWiper Data Wiper Malware Disrupts Ukrainian Critical Infrastructure in 2025 Attack (source)
- Critical Fortinet flaws now exploited in Qilin ransomware attacks (source)