Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical CI/CD Flaws Endanger Open Source Repositories

Critical CI/CD Flaws Endanger Open Source Repositories

Posted on June 24, 2026 By CWS

A newly discovered class of vulnerabilities in continuous integration and delivery (CI/CD) processes is leaving an immense number of open source repositories vulnerable to exploitation. Cybersecurity firm Novee has identified these flaws, named Cordyceps, which could allow attackers to take over developer workflows and seize control of repositories.

Understanding the Cordyceps Vulnerabilities

Novee reports that agentic coding practices are spreading insecure patterns across millions of repositories via automatically generated CI/CD workflows. These security flaws include command injection, authentication logic weaknesses, artifact poisoning, and privilege escalation, affecting tools from major organizations such as Microsoft, Google, Apache, Cloudflare, and the Python Software Foundation.

The vulnerabilities are particularly dangerous because they can be exploited by any unauthenticated attacker with a free account, allowing them to forge approvals, inject code, and extract credentials without needing special access or organizational membership.

Widespread Impact of the Flaws

During Novee’s investigations, 654 repositories were flagged in a single scan, with over 300 confirmed as fully exploitable. These vulnerabilities, located in GitHub Actions YAML files, can be triggered by low-privilege workflows initiated through untrusted pull requests or comments. The resulting high-privilege workflows could potentially authenticate to cloud providers using maintainer permissions.

This issue is not isolated to GitHub; it is a systemic problem affecting any CI/CD management system. When compromised software is deployed across numerous organizations, it can extend its reach to banks, cloud services, AI labs, and user devices.

Consequences for the Software Supply Chain

The exploitation of these vulnerabilities could lead to severe supply chain compromises. This includes publishing malicious packages on platforms like NPM, PyPI, Crates.io, Docker/GHCR, and Helm, as well as injecting unauthorized code into protected branches. Additionally, it may result in forced CI checks, stolen credentials across AWS, GCP, and Netlify, and compromised self-hosted runners.

Novee emphasizes that this vulnerability is deeply embedded in the open-source infrastructure that underpins much of the industry. It remains hidden from standard security scans because each component functions as intended; the risk emerges from untrusted data crossing unchecked trust boundaries.

The cybersecurity community must prioritize auditing CI/CD workflows as critical security components to prevent such systemic threats from causing widespread damage. Ongoing vigilance and proactive measures are essential to safeguarding the integrity of the software supply chain.

Security Week News Tags:artifact poisoning, CI/CD vulnerabilities, code injection, Cybersecurity, GitHub actions, Novee, open source security, privilege escalation, supply chain risk, unauthenticated attackers

Post navigation

Previous Post: AI Model Writes Rust-Based Windows Kernel Swiftly
Next Post: Massive FortiBleed Attack Breaches 430,000+ Firewalls

Related Posts

Citrix Patches Exploited NetScaler Zero-Day Citrix Patches Exploited NetScaler Zero-Day Security Week News
Alleged Chinese State Hacker Wanted by US Arrested in Italy Alleged Chinese State Hacker Wanted by US Arrested in Italy Security Week News
Chinese Hackers Breached Law Firm Williams & Connolly via Zero-Day Chinese Hackers Breached Law Firm Williams & Connolly via Zero-Day Security Week News
CodeSecCon Is Today: Where Software Security’s Next Chapter Unfolds (Virtual Event) CodeSecCon Is Today: Where Software Security’s Next Chapter Unfolds (Virtual Event) Security Week News
ClickFix Attacks Against macOS Users Evolving ClickFix Attacks Against macOS Users Evolving Security Week News
Sophisticated Koske Linux Malware Developed With AI Aid Sophisticated Koske Linux Malware Developed With AI Aid Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Levi Strauss Faces Cyber Intrusion via Social Engineering
  • Critical Flaw in Progress Kemp LoadMaster Listed by CISA
  • Atlassian Rovo AI Vulnerability Exposes Sensitive Data
  • N-central Hotfix 2 Released Amid Security Concerns
  • Revival of Bugtraq: Original Cybersecurity Forum Returns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Levi Strauss Faces Cyber Intrusion via Social Engineering
  • Critical Flaw in Progress Kemp LoadMaster Listed by CISA
  • Atlassian Rovo AI Vulnerability Exposes Sensitive Data
  • N-central Hotfix 2 Released Amid Security Concerns
  • Revival of Bugtraq: Original Cybersecurity Forum Returns

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark