logo

Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks

ID: 0a48bcfc-9145-5ca0-8b00-52cf45b8517e

STIX ID: report--0a48bcfc-9145-5ca0-8b00-52cf45b8517e

Feed Name: The Hacker News

Threat Score
88/100

Date Published: 2026-06-24

Date Updated: 2026-06-24

Author: [email protected] (The Hacker News)

...
...

Novee Security disclosed "Cordyceps," a critical CI/CD workflow misconfiguration pattern that allows unauthenticated users to hijack pull-request-triggered workflows to run arbitrary code, exfiltrate credentials, and compromise software supply chains; scans of ~30,000 repositories found over 300 fully exploitable projects affecting major organizations (Microsoft, Google, Apache, Cloudflare), with several vendors confirming impact and applying mitigations after responsible disclosure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.