Exploitable CI/CD Vulnerabilities Expose Millions of Repositories to Hijacking

General News

Summary

A new class of CI/CD vulnerabilities called Cordyceps exposes millions of repositories to takeover through insecure GitHub Actions workflow patterns. The flaw lets unauthenticated attackers hijack developer pipelines, forge approvals, push code, and steal credentials. Novee says the issue affects widely used open-source projects and can ripple into downstream organizations that depend on them. The exposure creates a supply-chain security problem for teams that build, sign, publish, or deploy software through automated workflows.

Classifications

industries
Entertainment
applications
Accounting and Taxes

AI Classifications

Labels
Cloud Infrastructure Software Cybersecurity Software Developer Tools

Linked Companies

Cloudflare
$1B+
Google LLC
$100M to $250M
Netlify
$10M to $25M
Novee
$1M to $5M