BTC $64,267.16 -1.39%
ETH $1,877.05 -2.49%
BNB $600.13 -1.24%
XRP $1.02 -2.05%
SOL $75.81 -1.62%
TRX $0.3306 +0.28%
DOGE $0.0695 -1.43%
ADA $0.1949 -1.23%
BCH $213.88 -1.89%
LINK $8.27 -0.72%
HYPE $54.17 -1.10%
AAVE $89.94 -1.84%
SUI $0.6886 -1.56%
XLM $0.1620 -0.61%
ZEC $500.55 -4.07%
BTC $64,267.16 -1.39%
ETH $1,877.05 -2.49%
BNB $600.13 -1.24%
XRP $1.02 -2.05%
SOL $75.81 -1.62%
TRX $0.3306 +0.28%
DOGE $0.0695 -1.43%
ADA $0.1949 -1.23%
BCH $213.88 -1.89%
LINK $8.27 -0.72%
HYPE $54.17 -1.10%
AAVE $89.94 -1.84%
SUI $0.6886 -1.56%
XLM $0.1620 -0.61%
ZEC $500.55 -4.07%

A high-risk vulnerability named "Cordyceps" has been exposed, affecting open-source repositories of major companies such as Microsoft and Google

2026-06-25 14:51:53

The Chief Information Security Officer of Slow Fog, 23pds, stated that researchers have exposed a high-risk vulnerability in CI/CD called Cordyceps, affecting the open-source repositories of major companies such as Microsoft, Google, Apache, and Cloudflare. Attackers do not need corporate accounts or any system permissions; they can simply register a free GitHub account, submit a malicious PR, and leave a comment to forge approvals, steal server keys, and push malicious code, completely taking control of the corporate code repository.

app_icon
ChainCatcher Building the Web3 world with innovations.