Close Menu
    What's Hot

    New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis

    The Ebola Outbreak’s Central Mystery: Where Did This Virus Come From?

    Inglewood wins a legal victory over its most famous building

    Facebook X (Twitter) Instagram
    Trending
    • New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis
    • The Ebola Outbreak’s Central Mystery: Where Did This Virus Come From?
    • Inglewood wins a legal victory over its most famous building
    • Venezuela Live Updates: Rescuers Search for Survivors After Worst Quakes in Decades
    • On the ground and online, Venezuelans desperately search for missing relatives.
    • The Aerogarden I Recommend to Everyone Is Just $83 Right Now, a 63 Percent Discount
    • Micron: Avoid Buying The Peak, You Might Thank Me Later (NASDAQ:MU)
    • Alexia Putellas: Former Barcelona midfielder decides to join London City Lionesses on a free transfer | Football News
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks

    adminBy adminJune 24, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Ravie LakshmananJun 24, 2026Open Source / Supply Chain Security

    Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks

    Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains.

    The “critical exploitable pattern” has been codenamed Cordyceps by Novee Security. The issue can allow full attacker control of repositories at dozens of the largest organizations worldwide, including Microsoft, Google, Apache, and Cloudflare.

    “The flaw is exploitable by any unauthenticated user,” Elad Meged, founding engineer and security researcher at Novee Security, said. “No org membership or special privileges; a free account is enough to forge approvals, push code, or steal credentials.”

    The penetration-testing company’s scan of about 30,000 high-impact repositories has revealed more than 300 to be fully exploitable, enabling attacker-controlled code execution, credential theft, and supply chain compromise, which can have severe downstream impacts.

    The core of the problem trickles down to weak CI/CD configurations that grant pull requests (PRs) more permissions than they should have. PRs are proposals to merge code changes from one branch into the main project. However, because an untrusted PR can trigger privileged workflows, it can open the door to command injection, privilege escalation, and supply chain compromise.

    Cybersecurity

    “This supply chain vulnerability lies in the foundational open-source plumbing the entire industry runs on, and the kind of issue that hides from scanners because, technically, every individual piece is working as designed,” Novee explained. “The workflow does what it was told. The vulnerability exists only in the composition – untrusted data crossing a trust boundary that no one audited.”

    On Microsoft’s Azure Sentinel, for example, Novee found a comment on a PR that could run anonymous attacker code on Microsoft’s CI and steal a non-expiring GitHub App key. In a similar case, a PR on Google’s AI Agent Development Kit (“adk-samples”) could execute attacker code on Google’s CI to gain complete authority over a Google Cloud repository.

    Other findings are listed below –

    • Apache Doris, where two zero-click attacks cause a single comment on any PR or a forked PR to run attacker code and exfiltrate hard-coded CI credentials or a token with full write permissions
    • Cloudflare Workers SDK, where a PR with a crafted branch name can execute arbitrary commands on Cloudflare’s CI runners
    • Python Software Foundation’s Black, where a single pull request from anyone could execute attacker code on Black’s build systems and steal the automation token, which can then be used to approve pull requests.

    Following responsible disclosure, both Microsoft and Google confirmed impact, while Cloudflare, Python, and Apache have applied hardening and patches, respectively.

    “The nature of agentic coding means these CI/CD vulnerabilities are reproduced persistently, at scale, ‘infecting’ repositories at an exponential rate,” Meged said. “Because anonymous users can use them to gain control over the software supply chain, we like to think of it as ‘puppeteering’ the repositories of some of the world’s biggest companies, silently manipulating their workflows.”

    Attacks CICD Cordyceps expose Flaws GitHub Repositories supplychain
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleHow Trillionaires Are Really Made by Nabil Ahmed
    Next Article Qualcomm Buys Buzzy Chip Startup Modular for Nearly $4 Billion
    admin
    • Website

    Related Posts

    New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis

    June 25, 2026

    Chrome Ad Blocker with 10M+ Installs Found with Dormant Script Injection Capability

    June 25, 2026

    Smart TV Proxyware, 24-Year curl Bug, AI Crime Forums + 13 More Stories

    June 25, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    New Gaslight macOS Malware Uses Prompt Injection to Disrupt AI-Assisted Analysis

    The Ebola Outbreak’s Central Mystery: Where Did This Virus Come From?

    Inglewood wins a legal victory over its most famous building

    Venezuela Live Updates: Rescuers Search for Survivors After Worst Quakes in Decades

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by