Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GitHub Enhances Security by Blocking Risky Pwn Requests

GitHub Enhances Security by Blocking Risky Pwn Requests

Posted on June 23, 2026 By CWS

GitHub has taken significant steps to bolster software supply chain security by updating its popular ‘actions/checkout’ tool. This update is designed to block pwn request attacks that exploit the ‘pull_request_target’ workflow trigger, which can potentially run malicious code with full workflow privileges. The change, effective from June 18, 2026, automatically blocks common pwn request patterns, marking an essential move for safeguarding repositories.

New Security Measures for Actions/Checkout

The latest update to ‘actions/checkout’ ensures that fork pull request codes are not fetched in ‘pull_request_target’ and ‘workflow_run’ workflows, particularly when the triggering event is a ‘pull_request’. This measure is in place unless the ‘allow-unsafe-pr-checkout’ flag is explicitly set to ‘true’. The update will extend to all major supported versions on July 16, 2026, enhancing security across the platform.

These preventative measures are crucial as ‘pull_request_target’ workflows often run with elevated permissions, including access to secrets and write capabilities via the GITHUB_TOKEN. Such access poses significant security risks if exploited by malicious actors through untrusted fork pull requests.

Understanding the Risks of Pull Request Target

‘Pull_request_target’ is a trigger that executes workflows automatically when a pull request is opened or updated. This convenience comes with risks, as the workflow runs with the base repository’s access levels, potentially exposing sensitive information. GitHub’s documentation warns that executing untrusted code through this mechanism can lead to vulnerabilities, including cache poisoning and unauthorized access.

The risk is heightened when combined with ‘actions/checkout’, allowing attackers to submit harmful scripts that, if executed, could compromise the GITHUB_TOKEN and other critical data. This type of attack, known as a pwn request, has been exploited in recent software supply chain attacks, including breaches involving the Nx build system and other popular packages.

Guidance for Developers

To mitigate risks, developers are advised to carefully assess the necessity of using ‘pull_request_target’. If elevated permissions are not required, switching to ‘pull_request’ can reduce potential vulnerabilities. Developers should also restrict workflow permissions and ensure that user-controlled inputs do not result in executing untrusted code.

GitHub emphasizes that while this update is a protective measure, it is not a comprehensive solution. Workflows with significant privileges still require thorough reviews to ensure security. By implementing these changes, GitHub aims to provide a safer environment for developers, minimizing the threat of malicious exploits.

Overall, this update is a critical step in strengthening the security of the software supply chain on GitHub. Developers are encouraged to review their workflows and adopt best practices to protect their repositories from potential threats.

The Hacker News Tags:actions/checkout, cache poisoning, code execution, fork pull requests, GitHub, GITHUB_TOKEN, malicious code, pull_request_target, pwn requests, Repository, Security, software chain attacks, software supply chain, workflow permissions, Workflow Security

Post navigation

Previous Post: Hackers Exploit Tools for Network Persistence
Next Post: Carl Froggett: Dual Role as CISO and CIO at Deep Instinct

Related Posts

Cybercriminals Clone Antivirus Site to Spread Venom RAT and Steal Crypto Wallets Cybercriminals Clone Antivirus Site to Spread Venom RAT and Steal Crypto Wallets The Hacker News
Megalodon Campaign Targets Thousands of GitHub Repositories Megalodon Campaign Targets Thousands of GitHub Repositories The Hacker News
Commvault CVE-2025-34028 Added to CISA KEV After Active Exploitation Confirmed Commvault CVE-2025-34028 Added to CISA KEV After Active Exploitation Confirmed The Hacker News
Learn How AI-Powered Zero Trust Detects Attacks with No Files or Indicators Learn How AI-Powered Zero Trust Detects Attacks with No Files or Indicators The Hacker News
Hackers Hijack Blender 3D Assets to Deploy StealC V2 Data-Stealing Malware Hackers Hijack Blender 3D Assets to Deploy StealC V2 Data-Stealing Malware The Hacker News
Linux AppArmor Vulnerabilities Risk Root Escalation Linux AppArmor Vulnerabilities Risk Root Escalation The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Dragos Launches EmberAI for Enhanced OT Cybersecurity
  • AI Skill Bypasses Security, Affects Thousands
  • Critical Dify Vulnerabilities Risk AI Data Leakage
  • FFmpeg Vulnerability Enables Remote Code Execution
  • LastPass Data Breach Exposes Customer Information via Klue

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Dragos Launches EmberAI for Enhanced OT Cybersecurity
  • AI Skill Bypasses Security, Affects Thousands
  • Critical Dify Vulnerabilities Risk AI Data Leakage
  • FFmpeg Vulnerability Enables Remote Code Execution
  • LastPass Data Breach Exposes Customer Information via Klue

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark