Critical AWS supply chain vulnerability could have let hackers take over key GitHub repositories



  • Wiz discovered AWS CodeBuild misconfiguration enabling unauthorized privileged builds, dubbed “CodeBreach.”
  • Flaw risked exposing GitHub tokens and enabling supply chain attacks across AWS projects
  • AWS fixed issue within 48 hours; no abuse detected, users urged to secure CI/CD setups

A critical misconfiguration in Amazon Web Services (AWS) CodeBuild service exposed several AWS-managed GitHub repositories to potential supply chain attacks, experts have warned.

Security researchers Wiz discovered the flaw and reported it to AWS, thus helping remedy the issue.


https://cdn.mos.cms.futurecdn.net/2viAsX89eJReYQEQ3i3SwH-750-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img