Security News

CISA Warns of Active Exploitation in GitHub Action Supply Chain Compromise
2025-03-19 05:05

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a vulnerability linked to the supply chain compromise of the GitHub Action, tj-actions/changed-files, to its Known...

GitHub Action hack likely led to another in cascading supply chain attack
2025-03-18 20:03

A cascading supply chain attack that began with the compromise of the "reviewdog/action-setup@v1" GitHub Action is believed to have led to the recent breach of "tj-actions/changed-files" that...

Google acquisition target Wiz links fresh supply chain attack to 23K pwned GitHub repos
2025-03-18 13:02

Ad giant just confirmed its cloudy arm will embrace security shop in $30B deal Wiz security researchers think they've found the root cause of the GitHub supply chain attack that unfolded over the...

Supply chain attack on popular GitHub Action exposes CI/CD secrets
2025-03-17 15:24

A supply chain attack on the widely used 'tj-actions/changed-files' GitHub Action, used by 23,000 repositories, potentially allowed threat actors to steal CI/CD secrets from GitHub Actions build...

GitHub supply chain attack spills secrets from 23,000 projects
2025-03-17 12:34

Large organizations among those cleaning up the mess It's not such a happy Monday for defenders wiping the sleep from their eyes only to deal with the latest supply chain attack.…

GitHub project maintainers targeted with fake security alert
2025-03-17 10:49

A phishing campaign targeting GitHub account owners has been trying to scare them with a fake security alert into allowing a malicious OAuth app access to their account and repositories. The fake...

GitHub Action Compromise Puts CI/CD Secrets at Risk in Over 23,000 Repositories
2025-03-17 10:11

Cybersecurity researchers are calling attention to an incident in which the popular GitHub Action tj-actions/changed-files was compromised to leak secrets from repositories using the continuous...

Fake "Security Alert" issues on GitHub use OAuth app to hijack accounts
2025-03-16 18:36

A widespread phishing campaign has targeted nearly 12,000 GitHub repositories with fake "Security Alert" issues, tricking developers into authorizing a malicious OAuth app that grants attackers...

GitHub Uncovers New ruby-saml Vulnerabilities Allowing Account Takeover Attacks
2025-03-13 12:26

Two high-severity security flaws have been disclosed in the open-source ruby-saml library that could allow malicious actors to bypass Security Assertion Markup Language (SAML) authentication...

Blind Eagle Hacks Colombian Institutions Using NTLM Flaw, RATs and GitHub-Based Attacks
2025-03-11 14:35

The threat actor known as Blind Eagle has been linked to a series of ongoing campaigns targeting Colombian institutions and government entities since November 2024. "The monitored campaigns...