Security issue in open source software leaves businesses concerned for systems

Estimated read time 3 min read




  • A popular tool for automated software updates was compromised via GitHub
  • A piece of malicious code was added, exposing user secrets
  • Dozens of organizations were harmed already, researchers said

Tens of thousands of organizations, from SMBs to large enterprises, were at risk of inadvertently exposing internal secrets after a supply-chain attack hit a GitHub account.

A threat actor compromised the GitHub account of the person(s) maintaining tj-actions/changed files, a tool that is part of a larger collection called tj-actions, which helps automate software updates, and is reportedly used by more than 23,000 organizations.



Source link

You May Also Like

More From Author

+ There are no comments

Add yours