Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
CI/CD Vulnerabilities Risk Supply Chain Security

CI/CD Vulnerabilities Risk Supply Chain Security

Posted on June 24, 2026 By CWS

Recent findings by cybersecurity experts have brought to light a significant vulnerability within CI/CD workflows, posing a threat to open-source supply chains. The issue, identified by Novee Security and named Cordyceps, highlights a critical pattern allowing unauthorized individuals to manipulate these workflows, impacting many major global companies.

Vulnerability Overview

Dubbed Cordyceps, this flaw can potentially enable attackers to gain control over repositories without needing special access. Elad Meged, a key engineer at Novee Security, emphasized that even users with basic, free accounts could exploit this flaw to forge approvals, inject code, or compromise credentials.

Analyzing around 30,000 high-impact repositories, the penetration-testing team discovered over 300 susceptible to full exploitation. This could lead to unauthorized code execution, theft of credentials, and broader supply chain disruptions, which might have severe downstream repercussions.

Implications of Weak CI/CD Configurations

The root cause of this vulnerability is attributed to weak configurations in CI/CD systems, allowing pull requests more permissions than necessary. Typically, pull requests are intended to integrate code changes, but if untrusted, they can trigger privileged workflows, potentially resulting in command injection and privilege escalation.

Novee Security explained that these vulnerabilities are embedded in the basic structure of open-source frameworks, often escaping detection by traditional scanners. They emphasize that the real threat stems from untrusted data breaching security boundaries that remain unmonitored.

Case Studies and Industry Response

Several instances have highlighted the risks associated with this vulnerability. For instance, a comment on a pull request in Microsoft’s Azure Sentinel could allow unauthorized execution of code, potentially leading to the theft of a GitHub App key. Similarly, a pull request in Google’s AI Agent Development Kit could grant complete control over a Google Cloud repository.

Other noted cases include Apache Doris and Cloudflare Workers SDK, where specific pull requests could execute malicious commands. The Python Software Foundation’s Black was also found vulnerable to unauthorized code execution by any pull request, threatening the integrity of their systems.

Following these discoveries, companies such as Microsoft and Google have acknowledged the impact, while entities like Cloudflare, Python, and Apache have implemented necessary hardening measures and patches to address the vulnerabilities.

Elad Meged stressed that these vulnerabilities are pervasive, capable of spreading rapidly among repositories, effectively allowing attackers to manipulate workflows silently across some of the largest corporations worldwide.

The Hacker News Tags:Apache, CI/CD security, Cloudflare, code execution, credential theft, Cybersecurity, GitHub vulnerabilities, Google, Microsoft, Novee Security, open source security, privilege escalation, security patches, supply chain attacks

Post navigation

Previous Post: Securing Privileged Access: Strategies to Prevent Breaches
Next Post: New macOS Exploit Silently Disables Security Tools

Related Posts

SysAid Flaws Under Active Attack Enable Remote File Access and SSRF SysAid Flaws Under Active Attack Enable Remote File Access and SSRF The Hacker News
Critical React2Shell Flaw Added to CISA KEV After Confirmed Active Exploitation Critical React2Shell Flaw Added to CISA KEV After Confirmed Active Exploitation The Hacker News
Scattered Spider Arrests, Car Exploits, macOS Malware, Fortinet RCE and More Scattered Spider Arrests, Car Exploits, macOS Malware, Fortinet RCE and More The Hacker News
Tudou Guarantee Marketplace Halts Telegram Transactions After Processing Over  Billion Tudou Guarantee Marketplace Halts Telegram Transactions After Processing Over $12 Billion The Hacker News
Cybersecurity Updates: Qualcomm Flaw and iOS Exploit Chains Cybersecurity Updates: Qualcomm Flaw and iOS Exploit Chains The Hacker News
Apple Patches Safari Vulnerability Also Exploited as Zero-Day in Google Chrome Apple Patches Safari Vulnerability Also Exploited as Zero-Day in Google Chrome The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New macOS Exploit Silently Disables Security Tools
  • CI/CD Vulnerabilities Risk Supply Chain Security
  • Securing Privileged Access: Strategies to Prevent Breaches
  • DraftKings Hacker Sentenced to 18 Months in Prison
  • Rise of AI-Powered Cyber Threats Shifts Security Landscape

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New macOS Exploit Silently Disables Security Tools
  • CI/CD Vulnerabilities Risk Supply Chain Security
  • Securing Privileged Access: Strategies to Prevent Breaches
  • DraftKings Hacker Sentenced to 18 Months in Prison
  • Rise of AI-Powered Cyber Threats Shifts Security Landscape

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark