A supply chain attack resulted in 218 GitHub repositories leaking sensitive information and secrets, according to Palo Alto Networks Unit 42. The breach involved the GitHub Action “tj-actions/changed-files” targeting one of Coinbase’s open-source projects. Although the attacker failed to use Coinbase secrets, they were able to inject code that leaked secrets from repositories using the workflow. The attack initially seemed to have impacted thousands of repositories, but further investigation revealed that the scope was smaller and mostly involved short-lived GITHUB_TOKENs.

Navigating Cybersecurity Frameworks – CISO Resource Guide
The role of the Chief Information Security Officer (CISO) is crucial amid evolving cyber threats. Selecting the right cybersecurity framework aligns risk management with organizational