Critical CI/CD Vulnerability Cordyceps Discovered in Microsoft, Google, Apache Open-Source Repos Today

According to PANews, citing security research from Slow Mist Chief Information Security Officer 23pds, a critical CI/CD vulnerability named Cordyceps was exposed today (June 25), affecting open-source repositories of Microsoft, Google, Apache, and Cloudflare. Attackers require only a free GitHub account to submit malicious pull requests and comments, enabling them to forge approvals, steal server credentials, push malicious code, and gain full control of enterprise code repositories without requiring corporate accounts or system permissions.
Disclaimer: The information on this page may come from third-party sources and is for reference only. It does not represent the views or opinions of Gate and does not constitute any financial, investment, or legal advice. Virtual asset trading involves high risk. Please do not rely solely on the information on this page when making decisions. For details, see the Disclaimer.
Comment
0/400
No comments