Defending SaaS & Cloud Workflows: Supply Chain Security Insights with Idan Cohen
ID: b3a91652-69ed-5edf-9d0e-67e90973abb1
STIX ID: report--b3a91652-69ed-5edf-9d0e-67e90973abb1
Feed Name: Mitiga
Threat Score
Mitiga Mic discusses a March 2025 GitHub Actions supply-chain compromise of the widely used 'changed-files' TJ Action that allowed malicious commits to trigger full memory dumps and expose secrets across thousands of organizations; the transcript explains how unscoped workflow inputs and misconfigurations enabled the attack and provides detection, response, and CI/CD hardening guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
