[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f_yZ8sLS51LuyRiGSVJztIMZ7TvRyJYxQcU1PzANGXVI":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":23,"created_at":24,"published_at":25,"article":26,"tags":30,"podcasts":49},"cd6c1d3f-13db-403a-a954-c054166596fc","cicd-misconfigurations-enable-supply-chain-hijacking-across-300-github-repos","e55a6e8c-c419-46d8-8935-0d7c8d928d15","CI\u002FCD Misconfigurations Enable Supply Chain Hijacking Across 300+ GitHub Repos","The Cordyceps vulnerability highlights how weak CI\u002FCD pipeline configurations can grant unauthenticated users the ability to execute arbitrary code and steal credentials within high-profile repositories. The root cause is excessive permissions assigned to pull request workflows, allowing anonymous contributors to trigger privileged pipeline actions without any authentication barrier. This matters enormously because compromised repositories from organizations like Microsoft, Google, and Apache can cascade malicious code downstream to millions of dependent projects and end users. Supply chain attacks of this nature are particularly dangerous as they abuse trusted build infrastructure, making detection difficult and the blast radius exceptionally wide.","**Immediate actions:**\n- Audit all CI\u002FCD workflow files for overly permissive `pull_request_target` triggers and restrict them to trusted contributors only.\n- Rotate any secrets, tokens, or credentials stored in affected repository environments that may have been exposed.\n- Disable or restrict write permissions granted to GitHub Actions workflows triggered by external pull requests.\n\n**Long-term improvements:**\n- Adopt least-privilege principles for all CI\u002FCD pipeline permissions, scoping tokens to only the minimum required actions.\n- Enforce required code reviews and branch protection rules before any workflow with elevated permissions can be triggered.\n- Implement a Software Composition Analysis (SCA) tool to continuously monitor third-party pipeline dependencies for tampering.\n\n**Detection measures:**\n- Enable GitHub audit logging and alert on anomalous workflow runs initiated by first-time or external contributors.\n- Monitor pipeline execution logs for unexpected secret access, outbound network calls, or artifact modifications.\n- Integrate SAST and secrets scanning tools directly into the CI\u002FCD pipeline to catch credential leakage before build completion.",[12,13,14,15,16,17,18,19,20,21,22],"CIS Control 4: Secure Configuration of Enterprise Assets","CIS Control 6: Access Control Management","CIS Control 16: Application Software Security","NIST SP 800-161: Supply Chain Risk Management","NIST AC-3: Access Enforcement","NIST AC-6: Least Privilege","NIST SA-12: Supply Chain Protection","NIST SI-3: Malicious Code Protection","SLSA Supply Chain Levels for Software Artifacts (Levels 2–4)","OpenSSF Scorecard: Token-Permissions and Dangerous-Workflow checks","OWASP CI\u002FCD Security Top 10: CICD-SEC-4 Poisoned Pipeline Execution","published","2026-06-24T14:21:04.904732+00:00","2026-06-24T14:21:04.764+00:00",{"id":7,"url":27,"slug":28,"title":29},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F06\u002Fcordyceps-cicd-flaws-expose-300-github.html","cordyceps-ci-cd-flaws-expose-300-github-repositories-to-supply-chain-attacks-2b8355","Cordyceps CI\u002FCD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks",[31,37,43],{"id":32,"name":33,"slug":34,"description":35,"color":36},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":38,"name":39,"slug":40,"description":41,"color":42},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":44,"name":45,"slug":46,"description":47,"color":48},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]