Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
A new form of CI/CD workflow vulnerability that enables attackers to take over workflows and disrupt open-source supply chains has been identified by cybersecurity researchers.
Novee Security has dubbed the "critical exploitable pattern" Cordyceps. Repositories at dozens of the biggest companies in the world, such as Microsoft, Google, Apache, and Cloudflare, are vulnerable to complete attacker control.
Elad Meged, a founding engineer and security researcher at Novee Security, stated that any unauthenticated user might exploit the vulnerability. A free account is sufficient to steal passwords, push code, and forge approvals without the need for an organization membership or specific rights.
More than 300 of the 30,000 high-impact repositories that the penetration-testing firm sca...

