Security issue in open source software leaves businesses concerned for systems

Security issue in open source software leaves businesses concerned for systems


  • A popular tool for automated software updates was compromised via GitHub
  • A piece of malicious code was added, exposing user secrets
  • Dozens of organizations were harmed already, researchers said

Tens of thousands of organizations, from SMBs to large enterprises, were at risk of inadvertently exposing internal secrets after a supply-chain attack hit a GitHub account.

A threat actor compromised the GitHub account of the person(s) maintaining tj-actions/changed files, a tool that is part of a larger collection called tj-actions, which helps automate software updates, and is reportedly used by more than 23,000 organizations.

link

Leave a Reply

Your email address will not be published. Required fields are marked *