National Cyber Warfare Foundation (NCWF)

GitHub Action Compromise Puts CI CD Secrets at Risk in Over 23,000 Repositories


0 user ratings
2025-03-18 17:04:34
milo
Blue Team (CND) , Attacks
Cybersecurity researchers are calling attention to an incident in which the popular GitHub Action tj-actions/changed-files was compromised to leak secrets from repositories using the continuous integration and continuous delivery (CI/CD) workflow.
The incident involved the tj-actions/changed-files GitHub Action, which is used in over 23,000 repositories. It's used to track and retrieve all



Source: TheHackerNews
Source Link: https://thehackernews.com/2025/03/github-action-compromise-puts-cicd.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)
Attacks



Copyright 2012 through 2025 - National Cyber Warfare Foundation - All rights reserved worldwide.