logo

Code to Cloud Attacks: From Github PAT to Cloud Control Plane

ID: 80d43b12-293c-5b36-9534-5668baff7012

STIX ID: report--80d43b12-293c-5b36-9534-5668baff7012

Feed Name: Wiz Blog

Threat Score
80/100

Date Published: 2025-12-09

Date Updated: 2026-05-01

...
...

Wiz documents active attacks in which compromised GitHub Personal Access Tokens are used to enumerate Actions secret names via API code search, create malicious workflows to exfiltrate or reuse secrets (including double-Base64 and webhook exfiltration), generate cloud credentials, and move laterally into cloud provider environments; the report highlights audit-log gaps, defense-evasion by deleting workflow artifacts, supply-chain implications, and recommends real-time log streaming, least-privilege secrets management, and secret scanning/remediation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.