Critical AWS supply chain vulnerability could have let hackers take over key GitHub repositories

Critical AWS supply chain vulnerability could have let hackers take over key GitHub repositories


  • Wiz discovered AWS CodeBuild misconfiguration enabling unauthorized privileged builds, dubbed “CodeBreach.”
  • Flaw risked exposing GitHub tokens and enabling supply chain attacks across AWS projects
  • AWS fixed issue within 48 hours; no abuse detected, users urged to secure CI/CD setups

A critical misconfiguration in Amazon Web Services (AWS) CodeBuild service exposed several AWS-managed GitHub repositories to potential supply chain attacks, experts have warned.

Security researchers Wiz discovered the flaw and reported it to AWS, thus helping remedy the issue.


link

Leave a Reply

Your email address will not be published. Required fields are marked *