VMTech
Discuss a project

Cordyceps: CI/CD Vulnerability Threatens 300+ GitHub Repositories

Cordyceps: CI/CD Vulnerability Threatens 300+ GitHub Repositories

Colleagues, a cybersecurity alert: sharing Novee Security's research on the Cordyceps pattern.

What happened:
- Novee demonstrated that weak CI/CD configurations let unauthenticated actors execute code, forge approvals, and exfiltrate tokens.
- Over 300 of ~30,000 audited repos (including Microsoft, Google, Apache, Cloudflare) were exploitable.
- After disclosure some organizations confirmed the issue; several projects have already applied patches.

Why it matters: the flaw enables supply-chain control and can cause widespread compromises.

Recommendations: verify PR/workflow permissions, remove secrets from CI, rotate tokens, and audit configs.

How will you respond to such risks?

#cybersecurity #supplychain #CI_CD #DevSecOps

Open analytics
On the site 0 views
min read 1 28.06.2026
On Instagram 3 views
On Instagram 1 reach
Instagram

Cordyceps: CI/CD Vulnerability Threatens 300+ GitHub Repositories

Open the post on Instagram ↗