Google acquisition target Wiz links fresh supply chain attack to 23K pwned GitHub repos
ID: 0e8ffaa0-5690-5452-bf39-faecd79da568
STIX ID: report--0e8ffaa0-5690-5452-bf39-faecd79da568
Feed Name: The Register (Security)
Threat Score
Researchers identified a chained supply‑chain attack: reviewdog/action-setup was briefly injected with malicious code to exfiltrate a PAT, which was then used to compromise tj-actions/changed-files and leak CI/CD secrets from more than 23,000 repositories. Affected users are advised to stop using the compromised Actions, replace or pin to safe versions, and rotate any exposed credentials.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
