Close Menu

    Subscribe to Updates

    Get the latest creative news from infofortech

    What's Hot

    Why Enterprise SaaS Deals Actually Stall: The Internal Friction Of The Buying Committee

    June 24, 2026

    Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks

    June 24, 2026

    Anthropic says AI needs regulation. But who chose to build it?

    June 24, 2026
    Facebook X (Twitter) Instagram
    InfoForTech
    • Home
    • Latest in Tech
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    Facebook X (Twitter) Instagram
    InfoForTech
    Home»Cybersecurity»Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
    Cybersecurity

    Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks

    InfoForTechBy InfoForTechJune 24, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email


    Ravie LakshmananJun 24, 2026Open Source / Supply Chain Security

    Cybersecurity researchers have flagged a new class of CI/CD workflow weakness that allows attackers to hijack workflows and compromise open-source supply chains.

    The “critical exploitable pattern” has been codenamed Cordyceps by Novee Security. The issue can allow full attacker control of repositories at dozens of the largest organizations worldwide, including Microsoft, Google, Apache, and Cloudflare.

    “The flaw is exploitable by any unauthenticated user,” Elad Meged, founding engineer and security researcher at Novee Security, said. “No org membership or special privileges; a free account is enough to forge approvals, push code, or steal credentials.”

    The penetration-testing company’s scan of about 30,000 high-impact repositories has revealed more than 300 to be fully exploitable, enabling attacker-controlled code execution, credential theft, and supply chain compromise, which can have severe downstream impacts.

    The core of the problem trickles down to weak CI/CD configurations that grant pull requests (PRs) more permissions than they should have. PRs are proposals to merge code changes from one branch into the main project. However, because an untrusted PR can trigger privileged workflows, it can open the door to command injection, privilege escalation, and supply chain compromise.

    “This supply chain vulnerability lies in the foundational open-source plumbing the entire industry runs on, and the kind of issue that hides from scanners because, technically, every individual piece is working as designed,” Novee explained. “The workflow does what it was told. The vulnerability exists only in the composition – untrusted data crossing a trust boundary that no one audited.”

    On Microsoft’s Azure Sentinel, for example, Novee found a comment on a PR that could run anonymous attacker code on Microsoft’s CI and steal a non-expiring GitHub App key. In a similar case, a PR on Google’s AI Agent Development Kit (“adk-samples”) could execute attacker code on Google’s CI to gain complete authority over a Google Cloud repository.

    Other findings are listed below –

    • Apache Doris, where two zero-click attacks cause a single comment on any PR or a forked PR to run attacker code and exfiltrate hard-coded CI credentials or a token with full write permissions
    • Cloudflare Workers SDK, where a PR with a crafted branch name can execute arbitrary commands on Cloudflare’s CI runners
    • Python Software Foundation’s Black, where a single pull request from anyone could execute attacker code on Black’s build systems and steal the automation token, which can then be used to approve pull requests.

    Following responsible disclosure, both Microsoft and Google confirmed impact, while Cloudflare, Python, and Apache have applied hardening and patches, respectively.

    “The nature of agentic coding means these CI/CD vulnerabilities are reproduced persistently, at scale, ‘infecting’ repositories at an exponential rate,” Meged said. “Because anonymous users can use them to gain control over the software supply chain, we like to think of it as ‘puppeteering’ the repositories of some of the world’s biggest companies, silently manipulating their workflows.”

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    InfoForTech
    • Website

    Related Posts

    Credential Traps to Detect Attacks Before Privilege Gain

    June 24, 2026

    FortiBleed Targeted FortiGate Firewalls in 110 Million-Credential Harvesting Operation

    June 23, 2026

    WhatsApp VBScript Campaign Uses Fake Documents to Install ManageEngine RMM Tool

    June 23, 2026

    29-Year-Old Squid Proxy Bug ‘Squidbleed’ Can Leak Cleartext HTTP Requests

    June 22, 2026

    The Gentlemen RaaS Uses GentleKiller EDR Framework Targeting 400 Security Processes

    June 22, 2026

    Unpatchable ‘usbliter8’ Exploit Breaks Apple A12 and A13 SecureROM Boot Chain

    June 21, 2026
    Leave A Reply Cancel Reply

    Advertisement
    Top Posts

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202616 Views

    This is the tech that makes Volvo’s latest EV a major step forward

    January 24, 202616 Views

    Why Security Validation Is Becoming Agentic

    March 16, 202615 Views
    Stay In Touch
    • Facebook
    • Twitter
    • Pinterest
    • Instagram
    • YouTube
    • Vimeo
    Advertisement
    About Us
    About Us

    Our mission is to deliver clear, reliable, and up-to-date information about the technologies shaping the modern world. We focus on breaking down complex topics into easy-to-understand insights for professionals, enthusiasts, and everyday readers alike.

    We're accepting new partnerships right now.

    Facebook X (Twitter) YouTube
    Most Popular

    DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

    March 20, 202638 Views

    Microsoft is bringing an AI helper to Xbox consoles

    March 14, 202616 Views

    This is the tech that makes Volvo’s latest EV a major step forward

    January 24, 202616 Views
    Categories
    • Artificial Intelligence
    • Cybersecurity
    • Innovation
    • Latest in Tech
    © 2026 All Rights Reserved InfoForTech.
    • Home
    • About Us
    • Contact Us
    • Privacy Policy

    Type above and press Enter to search. Press Esc to cancel.

    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.