Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
GitHub Enhances Security by Blocking Risky Pwn Requests

GitHub Enhances Security by Blocking Risky Pwn Requests

Posted on June 23, 2026 By CWS

GitHub has taken significant steps to bolster software supply chain security by updating its popular ‘actions/checkout’ tool. This update is designed to block pwn request attacks that exploit the ‘pull_request_target’ workflow trigger, which can potentially run malicious code with full workflow privileges. The change, effective from June 18, 2026, automatically blocks common pwn request patterns, marking an essential move for safeguarding repositories.

New Security Measures for Actions/Checkout

The latest update to ‘actions/checkout’ ensures that fork pull request codes are not fetched in ‘pull_request_target’ and ‘workflow_run’ workflows, particularly when the triggering event is a ‘pull_request’. This measure is in place unless the ‘allow-unsafe-pr-checkout’ flag is explicitly set to ‘true’. The update will extend to all major supported versions on July 16, 2026, enhancing security across the platform.

These preventative measures are crucial as ‘pull_request_target’ workflows often run with elevated permissions, including access to secrets and write capabilities via the GITHUB_TOKEN. Such access poses significant security risks if exploited by malicious actors through untrusted fork pull requests.

Understanding the Risks of Pull Request Target

‘Pull_request_target’ is a trigger that executes workflows automatically when a pull request is opened or updated. This convenience comes with risks, as the workflow runs with the base repository’s access levels, potentially exposing sensitive information. GitHub’s documentation warns that executing untrusted code through this mechanism can lead to vulnerabilities, including cache poisoning and unauthorized access.

The risk is heightened when combined with ‘actions/checkout’, allowing attackers to submit harmful scripts that, if executed, could compromise the GITHUB_TOKEN and other critical data. This type of attack, known as a pwn request, has been exploited in recent software supply chain attacks, including breaches involving the Nx build system and other popular packages.

Guidance for Developers

To mitigate risks, developers are advised to carefully assess the necessity of using ‘pull_request_target’. If elevated permissions are not required, switching to ‘pull_request’ can reduce potential vulnerabilities. Developers should also restrict workflow permissions and ensure that user-controlled inputs do not result in executing untrusted code.

GitHub emphasizes that while this update is a protective measure, it is not a comprehensive solution. Workflows with significant privileges still require thorough reviews to ensure security. By implementing these changes, GitHub aims to provide a safer environment for developers, minimizing the threat of malicious exploits.

Overall, this update is a critical step in strengthening the security of the software supply chain on GitHub. Developers are encouraged to review their workflows and adopt best practices to protect their repositories from potential threats.

The Hacker News Tags:actions/checkout, cache poisoning, code execution, fork pull requests, GitHub, GITHUB_TOKEN, malicious code, pull_request_target, pwn requests, Repository, Security, software chain attacks, software supply chain, workflow permissions, Workflow Security

Post navigation

Previous Post: Hackers Exploit Tools for Network Persistence
Next Post: Carl Froggett: Dual Role as CISO and CIO at Deep Instinct

Related Posts

Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers Russia-Linked APT28 Exploited MDaemon Zero-Day to Hack Government Webmail Servers The Hacker News
OneLogin Bug Let Attackers Use API Keys to Steal OIDC Secrets and Impersonate Apps OneLogin Bug Let Attackers Use API Keys to Steal OIDC Secrets and Impersonate Apps The Hacker News
Google Launches ‘Private AI Compute’ — Secure AI Processing with On-Device-Level Privacy Google Launches ‘Private AI Compute’ — Secure AI Processing with On-Device-Level Privacy The Hacker News
BadIIS Malware Spreads via SEO Poisoning — Redirects Traffic, Plants Web Shells BadIIS Malware Spreads via SEO Poisoning — Redirects Traffic, Plants Web Shells The Hacker News
Critical Cisco Vulnerability in Secure Workload API Patched Critical Cisco Vulnerability in Secure Workload API Patched The Hacker News
Google Requires Crypto App Licenses in 15 Regions as FBI Warns of .9M Scam Losses Google Requires Crypto App Licenses in 15 Regions as FBI Warns of $9.9M Scam Losses The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • FFmpeg Vulnerability Enables Remote Code Execution
  • LastPass Data Breach Exposes Customer Information via Klue
  • Critical Security Risks Uncovered in Dify AI Platform
  • Old Samsung KNOX Flaw Risks Galaxy Devices’ Security
  • Carl Froggett: Dual Role as CISO and CIO at Deep Instinct

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • FFmpeg Vulnerability Enables Remote Code Execution
  • LastPass Data Breach Exposes Customer Information via Klue
  • Critical Security Risks Uncovered in Dify AI Platform
  • Old Samsung KNOX Flaw Risks Galaxy Devices’ Security
  • Carl Froggett: Dual Role as CISO and CIO at Deep Instinct

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark