The compromise of GitHub Action tj-actions/changed-files has impacted only a small percentage of the 23,000 projects using it ...
CVE-2025-30066 supply chain attack compromised tj-actions on March 14, 2025, exposing 218 repositories and leaking ...
According to the cybersecurity firms analyzing the incident, the attacker initially tried to compromise the Coinbase ...
Stay informed with the latest in cybersecurity trends, vulnerabilities, and best practices. Don't miss out on this week's ...
Researchers claim primary target of a recent cascading supply chain attack was Coinbase The cryptocurrency exchange was not ...
StepSecurity disclosed a compromise of the popular GitHub Action tj-actions/changed-files, which works to detect file changes ...
A cascading supply chain attack that began with the compromise of the "reviewdog/action-setup@v1" GitHub Action is believed ...
Open source software used by more than 23,000 organizations, some of them in large enterprises, was compromised with ...
CISA confirms cascading attack from reviewdog to tj-actions exposed sensitive credentials across 23,000+ repositories.
Researchers from Palo Alto Networks said the hackers likely planned to leverage an open source project of the company for ...
A supply chain attack on a GitHub Actions tool has put up to 23,000 organisations at risk of having credentials stolen.
Attackers subverted a widely used tool for software development environment GitHub, potentially allowing them to steal ...