logo

GitHub Attack Vector Cracks Open Google, Microsoft, AWS Projects

ID: 4fc54f4c-86dd-5765-b002-0b432a0e8a20

STIX ID: report--4fc54f4c-86dd-5765-b002-0b432a0e8a20

Feed Name: Dark Reading

Threat Score
72/100

Date Published: 2024-08-14

Date Updated: 2026-04-21

Author: Elizabeth Montalbano, Contributing Writer

...
...

Unit 42 researchers disclosed an attack vector that abuses GitHub Actions artifacts to expose ephemeral GitHub tokens and third-party cloud credentials from open-source project workflows. The leaked tokens could allow attackers with repository read access to push malicious code through CI/CD pipelines or access secrets, impacting numerous high-profile projects; affected maintainers were notified and mitigations were applied, though other projects may still be at risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.