Security issue in open source software leaves businesses concerned for systems




  • A popular tool for automated software updates was compromised via GitHub
  • A piece of malicious code was added, exposing user secrets
  • Dozens of organizations were harmed already, researchers said

Tens of thousands of organizations, from SMBs to large enterprises, were at risk of inadvertently exposing internal secrets after a supply-chain attack hit a GitHub account.

A threat actor compromised the GitHub account of the person(s) maintaining tj-actions/changed files, a tool that is part of a larger collection called tj-actions, which helps automate software updates, and is reportedly used by more than 23,000 organizations.

https://cdn.mos.cms.futurecdn.net/kwd6rUGHDkeVy8hf2NCL48-1200-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

spot_imgspot_img