Close Menu
Global News HQ
    What's Hot

    Year of the stablecoin: The GENIUS Act, Wall Street, and the dollar’s digital leap

    July 27, 2025

    Why Small Business Must Adopt AI

    July 27, 2025

    Trump Wants Cane Sugar Coke: Will Soda Fans Pay Higher Prices and Taxes?

    July 27, 2025
    Recent Posts
    • Year of the stablecoin: The GENIUS Act, Wall Street, and the dollar’s digital leap
    • Why Small Business Must Adopt AI
    • Trump Wants Cane Sugar Coke: Will Soda Fans Pay Higher Prices and Taxes?
    • Citi Rewards+ Card rebrands as Citi Strata Card – The Points Guy
    • Wall Street Week Ahead
    Facebook X (Twitter) Instagram YouTube TikTok
    Trending
    • Year of the stablecoin: The GENIUS Act, Wall Street, and the dollar’s digital leap
    • Why Small Business Must Adopt AI
    • Trump Wants Cane Sugar Coke: Will Soda Fans Pay Higher Prices and Taxes?
    • Citi Rewards+ Card rebrands as Citi Strata Card – The Points Guy
    • Wall Street Week Ahead
    • 5 Predictions for 2025 Holiday Shopping
    • These Neuroprotective Nutrients Can Help Lower Your Dementia Risk
    • 10 Must-Know Tips for Growing Sweeter, Juicier Watermelons
    Global News HQ
    • Technology & Gadgets
    • Travel & Tourism (Luxury)
    • Health & Wellness (Specialized)
    • Home Improvement & Remodeling
    • Luxury Goods & Services
    • Home
    • Finance & Investment
    • Insurance
    • Legal
    • Real Estate
    • More
      • Cryptocurrency & Blockchain
      • E-commerce & Retail
      • Business & Entrepreneurship
      • Automotive (Car Deals & Maintenance)
    Global News HQ
    Home - Technology & Gadgets - Large enterprises scramble after supply-chain attack spills their secrets
    Technology & Gadgets

    Large enterprises scramble after supply-chain attack spills their secrets

    Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp VKontakte Email
    Large enterprises scramble after supply-chain attack spills their secrets
    Share
    Facebook Twitter LinkedIn Pinterest Email



    Open-source software used by more than 23,000 organizations, some of them in large enterprises, was compromised with credential-stealing code after attackers gained unauthorized access to a maintainer account, in the latest open-source supply-chain attack to roil the Internet.

    The corrupted package, tj-actions/changed-files, is part of tj-actions, a collection of files that’s used by more than 23,000 organizations. Tj-actions is one of many Github Actions, a form of platform for streamlining software available on the open-source developer platform. Actions are a core means of implementing what’s known as CI/CD, short for Continuous Integration and Continuous Deployment (or Continuous Delivery).

    Scraping server memory at scale

    On Friday or earlier, the source code for all versions of tj-actions/changed-files received unauthorized updates that changed the “tags” developers use to reference specific code versions. The tags pointed to a publicly available file that copies the internal memory of severs running it, searches for credentials, and writes them to a log. In the aftermath, many publicly accessible repositories running tj-actions ended up displaying their most sensitive credentials in logs anyone could view.

    “The scary part of actions is that they can often modify the source code of the repository that is using them and access any secret variables associated with a workflow,” HD Moore, founder and CEO of runZero and an expert in open-source security, said in an interview. “The most paranoid use of actions is to audit all of the source code, then pin the specific commit hash instead of the tag into the … the workflow, but this is a hassle.”



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr WhatsApp Email
    Previous ArticleRidley Scott’s Newest Opus? His French Wine.
    Next Article OKX suspends DEX aggregator to stop ‘further misuse’ by Lazarus

    Related Posts

    Your Comic-Con 2025 News: 'Peacemaker,' 'Starfleet Academy' and More Thrills

    July 27, 2025

    DOGE is reportedly pushing an AI tool that would put half of all federal regulations on a ‘delete list’

    July 27, 2025

    Astronomer taps Gwyneth Paltrow as ‘temporary’ spokesperson’ after Coldplay kiss cam scandal

    July 27, 2025

    Here are the laptops I’d tell any parent to consider for their back-to-school student

    July 26, 2025
    Leave A Reply Cancel Reply

    ads
    Don't Miss
    Cryptocurrency & Blockchain
    11 Mins Read

    Year of the stablecoin: The GENIUS Act, Wall Street, and the dollar’s digital leap

    Welcome to Slate Sundays, CryptoSlate’s new weekly feature showcasing in-depth interviews, expert analysis, and thought-provoking op-eds…

    Why Small Business Must Adopt AI

    July 27, 2025

    Trump Wants Cane Sugar Coke: Will Soda Fans Pay Higher Prices and Taxes?

    July 27, 2025

    Citi Rewards+ Card rebrands as Citi Strata Card – The Points Guy

    July 27, 2025
    Top
    Cryptocurrency & Blockchain
    11 Mins Read

    Year of the stablecoin: The GENIUS Act, Wall Street, and the dollar’s digital leap

    Welcome to Slate Sundays, CryptoSlate’s new weekly feature showcasing in-depth interviews, expert analysis, and thought-provoking op-eds…

    Why Small Business Must Adopt AI

    July 27, 2025

    Trump Wants Cane Sugar Coke: Will Soda Fans Pay Higher Prices and Taxes?

    July 27, 2025
    Our Picks
    Cryptocurrency & Blockchain
    11 Mins Read

    Year of the stablecoin: The GENIUS Act, Wall Street, and the dollar’s digital leap

    Welcome to Slate Sundays, CryptoSlate’s new weekly feature showcasing in-depth interviews, expert analysis, and thought-provoking op-eds…

    Business & Entrepreneurship
    1 Min Read

    Why Small Business Must Adopt AI

    With a little curiosity and the right guidance, AI might just become your most powerful…

    Pages
    • About Us
    • Contact Us
    • Disclaimer
    • Homepage
    • Privacy Policy
    Facebook X (Twitter) Instagram YouTube TikTok
    • Home
    © 2025 Global News HQ .

    Type above and press Enter to search. Press Esc to cancel.

    Go to mobile version