More details have come to light on the recent supply chain attack targeting GitHub Actions, including its root cause.
A potential supply chain attack on GitHub CodeQL started simply: a publicly exposed secret, valid for 1.022 seconds at a time. In that second, an attacker could take a series of steps that would allow ...
CVE-2025-30066 supply chain attack compromised tj-actions on March 14, 2025, exposing 218 repositories and leaking credentials.
Drawing lessons from the trials of 2025, some of the maturing methodologies behind those very considerable software supply ...
Researchers from Palo Alto Networks said the hackers likely planned to leverage an open source project of the company for ...
Threat actors are continuously evolving their tactics to exploit vulnerabilities and gain unauthorized access. That increasingly involves attacks targeting the software supply chain. The post The ...
The endgame of the recent cascading supply chain attack on GitHub was to breach Coinbase, one of the world’s most popular ...
Researchers have determined that Coinbase was the primary target in a recent GitHub Actions cascading supply chain attack ...
According to the cybersecurity firms analyzing the incident, the attacker initially tried to compromise the Coinbase ...
"Nation-state hacking has become more in your face," says Cleveland – who now works for network intel infosec outfit ExtraHop ...