Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CI/CD Vulnerabilities Risk Supply Chain Security

CI/CD Vulnerabilities Risk Supply Chain Security

Posted on June 24, 2026 By CWS

Recent findings by cybersecurity experts have brought to light a significant vulnerability within CI/CD workflows, posing a threat to open-source supply chains. The issue, identified by Novee Security and named Cordyceps, highlights a critical pattern allowing unauthorized individuals to manipulate these workflows, impacting many major global companies.

Vulnerability Overview

Dubbed Cordyceps, this flaw can potentially enable attackers to gain control over repositories without needing special access. Elad Meged, a key engineer at Novee Security, emphasized that even users with basic, free accounts could exploit this flaw to forge approvals, inject code, or compromise credentials.

Analyzing around 30,000 high-impact repositories, the penetration-testing team discovered over 300 susceptible to full exploitation. This could lead to unauthorized code execution, theft of credentials, and broader supply chain disruptions, which might have severe downstream repercussions.

Implications of Weak CI/CD Configurations

The root cause of this vulnerability is attributed to weak configurations in CI/CD systems, allowing pull requests more permissions than necessary. Typically, pull requests are intended to integrate code changes, but if untrusted, they can trigger privileged workflows, potentially resulting in command injection and privilege escalation.

Novee Security explained that these vulnerabilities are embedded in the basic structure of open-source frameworks, often escaping detection by traditional scanners. They emphasize that the real threat stems from untrusted data breaching security boundaries that remain unmonitored.

Case Studies and Industry Response

Several instances have highlighted the risks associated with this vulnerability. For instance, a comment on a pull request in Microsoft’s Azure Sentinel could allow unauthorized execution of code, potentially leading to the theft of a GitHub App key. Similarly, a pull request in Google’s AI Agent Development Kit could grant complete control over a Google Cloud repository.

Other noted cases include Apache Doris and Cloudflare Workers SDK, where specific pull requests could execute malicious commands. The Python Software Foundation’s Black was also found vulnerable to unauthorized code execution by any pull request, threatening the integrity of their systems.

Following these discoveries, companies such as Microsoft and Google have acknowledged the impact, while entities like Cloudflare, Python, and Apache have implemented necessary hardening measures and patches to address the vulnerabilities.

Elad Meged stressed that these vulnerabilities are pervasive, capable of spreading rapidly among repositories, effectively allowing attackers to manipulate workflows silently across some of the largest corporations worldwide.

The Hacker News Tags:Apache, CI/CD security, Cloudflare, code execution, credential theft, Cybersecurity, GitHub vulnerabilities, Google, Microsoft, Novee Security, open source security, privilege escalation, security patches, supply chain attacks

Post navigation

Previous Post: Securing Privileged Access: Strategies to Prevent Breaches
Next Post: New macOS Exploit Silently Disables Security Tools

Related Posts

Chinese TA415 Uses VS Code Remote Tunnels to Spy on U.S. Economic Policy Experts Chinese TA415 Uses VS Code Remote Tunnels to Spy on U.S. Economic Policy Experts The Hacker News
Adobe Reader Zero-Day Exploit Targets Users Since Late 2025 Adobe Reader Zero-Day Exploit Targets Users Since Late 2025 The Hacker News
React2Shell Vulnerability Actively Exploited to Deploy Linux Backdoors React2Shell Vulnerability Actively Exploited to Deploy Linux Backdoors The Hacker News
Deepfake Defense in the Age of AI Deepfake Defense in the Age of AI The Hacker News
Google’s New AI Doesn’t Just Find Vulnerabilities — It Rewrites Code to Patch Them Google’s New AI Doesn’t Just Find Vulnerabilities — It Rewrites Code to Patch Them The Hacker News
North Korean Hackers Use EtherHiding to Hide Malware Inside Blockchain Smart Contracts North Korean Hackers Use EtherHiding to Hide Malware Inside Blockchain Smart Contracts The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AIVEX: A New Model to Mitigate Supply Chain Risks
  • Public PoC Exploit for libssh2 RCE Vulnerability Unveiled
  • New macOS Exploit Silently Disables Security Tools
  • CI/CD Vulnerabilities Risk Supply Chain Security
  • Securing Privileged Access: Strategies to Prevent Breaches

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AIVEX: A New Model to Mitigate Supply Chain Risks
  • Public PoC Exploit for libssh2 RCE Vulnerability Unveiled
  • New macOS Exploit Silently Disables Security Tools
  • CI/CD Vulnerabilities Risk Supply Chain Security
  • Securing Privileged Access: Strategies to Prevent Breaches

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark