Researchers say compromised tool in the GitHub CI/CD environment stole credentials; infosec leaders need to act immediately.
More details have come to light on the recent supply chain attack targeting GitHub Actions, including its root cause.
Researchers have determined that Coinbase was the primary target in a recent GitHub Actions cascading supply chain attack ...
The compromise of GitHub Action tj-actions/changed-files has impacted only a small percentage of the 23,000 projects using it ...
Researchers from Palo Alto Networks said the hackers likely planned to leverage an open source project of the company for ...
The GitHub Action supply chain compromise that threatened the security of more than 23,000 repositories appears to be linked ...
CISA confirms cascading attack from reviewdog to tj-actions exposed sensitive credentials across 23,000+ repositories.
CISA warns of CVE-2025-30066, a GitHub supply chain attack exposing secrets via compromised actions logs. Update ...
The tj-actions/changed-files GitHub Action, which is used in 23,000 repositories, has been targeted in a supply chain attack.
GitHub Action tj-actions/changed-files was compromised, leaking CI/CD secrets. Users must update immediately to prevent ...
StepSecurity disclosed a compromise of the popular GitHub Action tj-actions/changed-files, which works to detect file changes ...
Tens of thousands of repositories have fallen victim to a supply chain attack via a GitHub Action. Security specialists at ...