Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

Researchers have identified a class of CI/CD configuration weaknesses, dubbed ‘Cordyceps,’ affecting more than 300 high-impact GitHub repositories, including those maintained by Microsoft, Google, Apache, and Cloudflare. The weakness allows external contributors with little or no privileges to trigger GitHub Actions workflows that execute code with elevated permissions, enabling theft of secrets and credentials stored in CI/CD pipelines. If exploited, attackers can tamper with build artifacts or package releases, turning trusted software into a vehicle for downstream supply chain compromise across any organization consuming those packages.

Author

Tech Jacks Solutions