Tech

Security issue in open source software leaves businesses concerned for systems

Share
Share


  • A popular tool for automated software updates was compromised via GitHub
  • A piece of malicious code was added, exposing user secrets
  • Dozens of organizations were harmed already, researchers said

Tens of thousands of organizations, from SMBs to large enterprises, were at risk of inadvertently exposing internal secrets after a supply-chain attack hit a GitHub account.

A threat actor compromised the GitHub account of the person(s) maintaining tj-actions/changed files, a tool that is part of a larger collection called tj-actions, which helps automate software updates, and is reportedly used by more than 23,000 organizations.

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Related Articles