CISA confirms cascading attack from reviewdog to tj-actions exposed sensitive credentials across 23,000+ repositories.
The open source tool tjactions/changed-files searched for sensitive information in the CI process with GitHub Actions and ...
A cascading supply chain attack that began with the compromise of the "reviewdog/action-setup@v1" GitHub Action is believed ...
A supply chain attack on the widely used 'tj-actions/changed-files' GitHub Action, used by 23,000 repositories, potentially ...
A compromise of the popular GitHub Actions tool turned into a massive supply chain attack, at this point thought to be ...
Tens of thousands of repositories have fallen victim to a supply chain attack via a GitHub Action. Security specialists at ...
GitHub Action tj-actions/changed-files was compromised, leaking CI/CD secrets. Users must update immediately to prevent ...
Large organizations among those cleaning up the mess It's not such a happy Monday for defenders wiping the sleep from their ...
A popular tool for automated software updates was compromised via GitHub A piece of malicious code was added, exposing user ...
A supply chain attack on a GitHub Actions tool has put up to 23,000 organisations at risk of having credentials stolen.