Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Official RVTools Website Hacked to deliver malicious Bumblebe software

May 19, 2025

Band

May 19, 2025

Firefox Patches 2 Zero-Day

May 19, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Compromise GITHUB action threatens CI/CD -Celes in more than 23,000 repositories
Global Security

Compromise GITHUB action threatens CI/CD -Celes in more than 23,000 repositories

AdminBy AdminMarch 17, 2025No Comments3 Mins Read
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


March 17, 2025Red LakshmananVulnerability / cloud security

Cybersecurity researchers pay attention to the incident in which the popular GitHub TJ-Actions/Change-Files were compromised to leak secrets from storage, using the workflow of continuous integration and permanent delivery (CI/CD).

A incident related TJ-action/Changed movies GitHub action used in more than 23,000 repositories. It is used to track and search all modified files and directors.

The compromise of the supply chain has been assigned an ID CVE Cve-2025-30066 (CVSS assessment: 8.6). The incident is said to have happened somewhere until March 14, 2025.

Cybersecurity

“In this attack, the attackers changed the action code and the back number updated several versions to refer to – Note. “Courageous actions Print CI/CD in GitHub Actions Build Logs.”

The pure result of this behavior is that in the event that the work process is publicly accessible, they can lead to unauthorized impact of sensitive secrets when the action is launched on storage.

These include AWS Access keys, GitHub Personal Stamps (PATS), NPM tokens and RSA private keys, among others. Given this, there is no evidence that the secrets leaks were aimed at any infrastructure controlled by the attacker.

In particular, angrily inserted code Designed to launch the Python scenario located on GitHub Gist, which reset CI/CD secrets from the Runner worker process. It is said that happened from an unverified source code. GitHub Gist has been lifted since then.

The Podkozakers project stated that an unknown threatening actor (s), who is behind the incident, was threatened with a personal access sign GitHub (PAT) used by @tj-actions-bot, a bot with a privileged repository access.

After detecting the account password, the authentication was upgraded for the use of Passkey, and its permission level was updated in such a way that it follows from the principle of the slightest privilege. GitHub also withdrawn the compromised Pat.

“Personal access suffered by the secrecy of GitHub, which has been canceled since then,” – supporters added. “Going forward, Pat will not be used for all projects in TJ-Actions to prevent the risk of re-occurrence.”

Cybersecurity

Everyone who uses GitHub action is recommended to update to The last version (46.0.1) as soon as possible. Users are also advised to consider all the workflows performed from March 14 to March 15, and check the “Unexpected Exit in the Movie Movies section.”

Development once again emphasizes how open source software remains particularly sensitive to the risks of the supply chain, which can have serious consequences for several customers down at the same time.

“As of March 15, 2025, all versions of TJ-Actions/Changes were affected – Note.

“Customers who used the hash version of TJ-Actions/Changer-Files would not affect if they did not update the hash during operation.”

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Official RVTools Website Hacked to deliver malicious Bumblebe software

May 19, 2025

Band

May 19, 2025

Firefox Patches 2 Zero-Day

May 19, 2025

Why CTEM – This is a winning rate for CISO in 2025

May 19, 2025

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Official RVTools Website Hacked to deliver malicious Bumblebe software

May 19, 2025

Band

May 19, 2025

Firefox Patches 2 Zero-Day

May 19, 2025

Why CTEM – This is a winning rate for CISO in 2025

May 19, 2025

New Httpbot Botnet Launches 200+ Precision Ddos Attacks to Game and Technology Sectors

May 16, 2025

10 best practices for effective data protection

May 16, 2025

Rat Remcos delivered via LNK files and mshta in attacks based on PowerShell

May 16, 2025

Researchers put up new flaws of the Intel processor that allows for memory leaks and attacks Spectre V2

May 16, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Official RVTools Website Hacked to deliver malicious Bumblebe software

May 19, 2025

Band

May 19, 2025

Firefox Patches 2 Zero-Day

May 19, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.