掃碼下載
BTC $66,287.85 -6.32%
ETH $1,838.30 -7.97%
BNB $636.04 -7.79%
XRP $1.21 -5.70%
SOL $73.25 -9.09%
TRX $0.3296 -3.44%
DOGE $0.0921 -8.23%
ADA $0.2101 -7.15%
BCH $246.10 -15.01%
LINK $8.27 -7.52%
HYPE $71.81 -3.67%
AAVE $73.56 -7.23%
SUI $0.8047 -7.29%
XLM $0.2206 -5.94%
ZEC $610.38 +7.22%
BTC $66,287.85 -6.32%
ETH $1,838.30 -7.97%
BNB $636.04 -7.79%
XRP $1.21 -5.70%
SOL $73.25 -9.09%
TRX $0.3296 -3.44%
DOGE $0.0921 -8.23%
ADA $0.2101 -7.15%
BCH $246.10 -15.01%
LINK $8.27 -7.52%
HYPE $71.81 -3.67%
AAVE $73.56 -7.23%
SUI $0.8047 -7.29%
XLM $0.2206 -5.94%
ZEC $610.38 +7.22%

慢霧餘弦:Coinbase 曾遭 GitHub Actions CI/CD 機制供應鏈攻擊,建議企業自查相關風險

2025-03-23 16:07:55
收藏

ChainCatcher 消息,慢霧餘弦在 X 平台發文稱,利用 GitHub Actions CI/CD 機制供應鏈攻擊 Coinbase,所幸沒有繼續成功,否則下一個被爆的安全事件就是針對 Coinbase 了。在 GitHub 上的供應鏈攻擊路徑:reviewdog/action-setup -> tj-actions/changed-files -> coinbase/agentkit ->竊取 GitHub Personal Access Token(PAT)、雲服務有關密鑰等。餘弦建議,如果企業用到 reviewdog 或 tj-actions,應該進行自查。

app_icon
ChainCatcher 與創新者共建Web3世界