CISA confirms cascading attack from reviewdog to tj-actions exposed sensitive credentials across 23,000+ repositories.
The compromise of GitHub Action tj-actions/changed-files has impacted only a small percentage of the 23,000 projects using it ...
A supply chain attack on the widely used 'tj-actions/changed-files' GitHub Action, used by 23,000 repositories, potentially ...
A compromise of the popular GitHub Actions tool turned into a massive supply chain attack, at this point thought to be ...
CVE-2025-30066 supply chain attack compromised tj-actions on March 14, 2025, exposing 218 repositories and leaking credentials.
More details have come to light on the recent supply chain attack targeting GitHub Actions, including its root cause.
Tens of thousands of repositories have fallen victim to a supply chain attack via a GitHub Action. Security specialists at ...
CISA warns of CVE-2025-30066, a GitHub supply chain attack exposing secrets via compromised actions logs. Update ...
According to the cybersecurity firms analyzing the incident, the attacker initially tried to compromise the Coinbase ...
The endgame of the recent cascading supply chain attack on GitHub was to breach Coinbase, one of the world’s most popular ...
A potential supply chain attack on GitHub CodeQL started simply: a publicly exposed secret, valid for 1.022 seconds at a time. In that second, an attacker could take a series of steps that would allow ...