扫码下载
BTC $59,680.26 -0.46%
ETH $1,588.27 +0.31%
BNB $554.29 -0.17%
XRP $1.04 -0.02%
SOL $74.37 +1.88%
TRX $0.3194 -0.64%
DOGE $0.0724 -1.18%
ADA $0.1445 -0.53%
BCH $200.63 +3.26%
LINK $7.30 -0.57%
HYPE $65.80 +5.56%
AAVE $89.70 -4.35%
SUI $0.6941 +0.27%
XLM $0.1816 +5.10%
ZEC $398.83 +4.10%
BTC $59,680.26 -0.46%
ETH $1,588.27 +0.31%
BNB $554.29 -0.17%
XRP $1.04 -0.02%
SOL $74.37 +1.88%
TRX $0.3194 -0.64%
DOGE $0.0724 -1.18%
ADA $0.1445 -0.53%
BCH $200.63 +3.26%
LINK $7.30 -0.57%
HYPE $65.80 +5.56%
AAVE $89.70 -4.35%
SUI $0.6941 +0.27%
XLM $0.1816 +5.10%
ZEC $398.83 +4.10%

名为 “Cordyceps” 的 CI/CD 高危漏洞曝光,微软、谷歌等多个头部企业开源仓库中招

2026-06-25 14:51:53
收藏

ChainCatcher 消息,慢雾首席信息安全官 23pds 发文称,研究员曝光了一类名为 Cordyceps 的 CI/CD 高危风险,微软、谷歌、Apache、Cloudflare 等头部企业的开源仓库全都实测中招。攻击者不用企业账号、不用任何系统权限,仅注册一个免费 GitHub 账号,提交一段恶意 PR、留一条评论,就能伪造审批、偷取服务器密钥、推送恶意代码,完全掌控企业代码仓库。

app_icon
ChainCatcher 与创新者共建Web3世界