GitHub Attack Vector Cracks Open Google, Microsoft, AWS Projects
ID: 4fc54f4c-86dd-5765-b002-0b432a0e8a20
STIX ID: report--4fc54f4c-86dd-5765-b002-0b432a0e8a20
Feed Name: Dark Reading
Date Published: 2024-08-14
Date Updated: 2026-04-21
Author: Elizabeth Montalbano, Contributing Writer
Unit 42 researchers disclosed an attack vector that abuses GitHub Actions artifacts to expose ephemeral GitHub tokens and third-party cloud credentials from open-source project workflows. The leaked tokens could allow attackers with repository read access to push malicious code through CI/CD pipelines or access secrets, impacting numerous high-profile projects; affected maintainers were notified and mitigations were applied, though other projects may still be at risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
