cognitive cybersecurity intelligence

News and Analysis

Search

Large enterprises scramble after supply-chain attack spills their secrets

Open-source software used by over 23,000 organisations was compromised by attackers who accessed a maintainer account, injecting credential-stealing code. The corrupted package, part of tj-actions, was able to modify source code and potentially access secret variables. The breach exposed some organisations’ sensitive credentials in freely accessible logs, underlining the need for stringent security protocols in open-source environments.

Source: arstechnica.com –

Subscribe to newsletter

Subscribe to HEAL Security Dispatch for the latest healthcare cybersecurity news and analysis.

More Posts