BTC $64,964.18 +0.74%
ETH $1,927.88 +1.26%
BNB $587.41 +3.34%
XRP $1.08 +1.03%
SOL $74.62 +1.39%
TRX $0.3280 +0.51%
DOGE $0.0704 -0.01%
ADA $0.1681 +2.36%
BCH $220.49 +4.76%
LINK $8.51 +2.36%
HYPE $53.59 -3.05%
AAVE $99.54 +1.20%
SUI $0.6962 +1.31%
XLM $0.1732 -0.30%
ZEC $476.12 +2.34%
BTC $64,964.18 +0.74%
ETH $1,927.88 +1.26%
BNB $587.41 +3.34%
XRP $1.08 +1.03%
SOL $74.62 +1.39%
TRX $0.3280 +0.51%
DOGE $0.0704 -0.01%
ADA $0.1681 +2.36%
BCH $220.49 +4.76%
LINK $8.51 +2.36%
HYPE $53.59 -3.05%
AAVE $99.54 +1.20%
SUI $0.6962 +1.31%
XLM $0.1732 -0.30%
ZEC $476.12 +2.34%

A high-risk vulnerability named "Cordyceps" has been exposed, affecting open-source repositories of major companies such as Microsoft and Google

2026-06-25 14:51:53
Collection

The Chief Information Security Officer of Slow Fog, 23pds, stated that researchers have exposed a high-risk vulnerability in CI/CD called Cordyceps, affecting the open-source repositories of major companies such as Microsoft, Google, Apache, and Cloudflare. Attackers do not need corporate accounts or any system permissions; they can simply register a free GitHub account, submit a malicious PR, and leave a comment to forge approvals, steal server keys, and push malicious code, completely taking control of the corporate code repository.

app_icon
ChainCatcher Building the Web3 world with innovations.