National Cyber Warfare Foundation (NCWF)

Elementary Data Compromised in Supply Chain Attack (Campaign)


0 user ratings
2026-05-11 15:07:06
milo
Attacks
The compromise originated from a GitHub Actions script injection vulnerability in a workflow that improperly handled untrusted input from pull request comments. An attacker exploited this flaw to execute arbitrary commands within the CI pipeline, gaining access to the reposito...

The compromise originated from a GitHub Actions script injection vulnerability in a workflow that improperly handled untrusted input from pull request comments. An attacker exploited this flaw to execute arbitrary commands within the CI pipeline, gaining access to the reposito...

Source: Wiz
Source Link: https://threats.wiz.io/all-incidents/elementary-data-compromised-in-supply-chain-attack


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Attacks



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.