跳到正文
原文
The Hacker News· [email protected] (The Hacker News)·· 4 小时前精选AI 评分83

研究人员披露 GhostAction 通过恶意 GitHub Actions 工作流窃取凭据

Credential-Stealing GitHub Actions Workflows Planted in Tens of Thousands of Repositories

AI 导读

研究人员披露,GhostAction 供应链攻击利用受侵的 GitHub 维护者账号,将名为“Security Audit”或“GitHub Actions Security”的恶意工作流植入大量仓库。

推荐理由

披露了通过维护者账号向数万仓库植入恶意 GitHub Actions 工作流的攻击链、泄露凭据范围及处置方法,可帮助团队排查仓库、轮换密钥并降低供应链风险。

来源:The Hacker News · thehackernews.com