discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks

Cordyceps CI/CD flaws expose 300+ GitHub repositories to supply-chain attacks. The issue allows attackers to hijack workflows and compromise open-source supply chains.

By Ravie Lakshmanan·Jun 24·thehackernews.com·1 min read

Intelligence analysis by Llama 3.3 70B

Cordyceps CI/CD Flaws Expose 300+ GitHub Repositories to Supply-Chain Attacks
Image: thehackernews.com

A new class of CI/CD workflow weakness, codenamed Cordyceps, has been discovered, allowing attackers to hijack workflows and compromise open-source supply chains.

Why it matters

The Cordyceps flaw has severe downstream impacts, enabling attacker-controlled code execution, credential theft, and supply chain compromise, affecting dozens of the largest organizations worldwide.

Imagine a big library where people share code. The Cordyceps flaw is like a secret door that lets bad people sneak in and change the code without permission, which can cause big problems.

Analysis

Introduction to Cordyceps Flaw

The Cordyceps flaw is a critical exploitable pattern in CI/CD workflows that allows attackers to hijack workflows and compromise open-source supply chains. According to Elad Meged, founding engineer and security researcher at Novee Security, the flaw is exploitable by any unauthenticated user, requiring only a free account to forge approvals, push code, or steal credentials.

Impact of the Flaw

The Cordyceps flaw has severe downstream impacts, enabling attacker-controlled code execution, credential theft, and supply chain compromise. Novee Security's scan of about 30,000 high-impact repositories has revealed more than 300 to be fully exploitable. The flaw affects dozens of the largest organizations worldwide, including Microsoft, Google, Apache, and Cloudflare.

Technical Details of the Flaw

The core of the problem lies in weak CI/CD configurations that grant pull requests (PRs) more permissions than they should have. PRs are proposals to merge code changes from one branch into the main project. However, because an untrusted PR can trigger privileged workflows, it can open the door to command injection, privilege escalation, and supply chain compromise. The vulnerability exists only in the composition – untrusted data crossing a trust boundary that no one audited.

Key points

  • Cordyceps flaw exposes 300+ GitHub repositories to supply-chain attacks
  • The flaw allows attackers to hijack workflows and compromise open-source supply chains
  • It affects dozens of the largest organizations worldwide, including Microsoft, Google, Apache, and Cloudflare
The Upside

The discovery of the Cordyceps flaw can lead to improved CI/CD security practices, and organizations can take steps to harden their workflows and prevent such attacks. By addressing this vulnerability, the open-source community can become more secure.

The Downside

The Cordyceps flaw poses a significant risk to the security of open-source supply chains, and if left unaddressed, it can lead to severe consequences, including compromised repositories and stolen credentials. The fact that it can be exploited by any unauthenticated user makes it a pressing concern.

Originally reported at

thehackernews.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritygithubopen-sourcesupply-chain-security

Author

Ravie Lakshmanan

Intelligence analysis by

Llama 3.3 70B

Published

Jun 24, 2026

Source

thehackernews.com

Share

Topics

securitygithubopen-sourcesupply-chain-security

Related

More from this desk

Aug 24·bleepingcomputer.com

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

ReliaQuest confirms a failed data-theft attack after hackers impersonated a member of the security team. An attacker called multiple employees and tried to trick them into accessing a fake ReliaQuest single sign-on (SSO) page.

Aug 24·bleepingcomputer.com

Microsoft Teams now lets admins block external bots from meetings

Microsoft is rolling out a Teams meeting protection policy that lets administrators automatically block identified external bots from joining meetings, without requiring organizer approval.

Aug 24·bleepingcomputer.com

Microsoft: August updates break printing, PDF export in WPF apps

Microsoft has confirmed that .NET Framework updates released as part of the August 2026 Patch Tuesday are breaking printing and PDF export in some applications. The issue affects only apps that use the Windows Presentation Foundation (WPF) UI framework.

Aug 24·thehackernews.com

WordlistLoader Delivers Amatera via ClickFix, SynkLoader Phishes Windows Passwords

Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups.