BTC $62,658.95 -1.68%
ETH $1,868.82 -1.15%
BNB $606.16 -1.14%
XRP $1.00 -0.74%
SOL $75.64 -0.71%
TRX $0.3333 -1.01%
DOGE $0.0696 -1.24%
ADA $0.1816 -2.13%
BCH $205.52 -4.38%
LINK $8.72 -0.28%
HYPE $56.72 -0.34%
AAVE $87.25 -1.85%
SUI $0.6791 -1.39%
XLM $0.1585 -1.51%
ZEC $486.19 -1.98%
BTC $62,658.95 -1.68%
ETH $1,868.82 -1.15%
BNB $606.16 -1.14%
XRP $1.00 -0.74%
SOL $75.64 -0.71%
TRX $0.3333 -1.01%
DOGE $0.0696 -1.24%
ADA $0.1816 -2.13%
BCH $205.52 -4.38%
LINK $8.72 -0.28%
HYPE $56.72 -0.34%
AAVE $87.25 -1.85%
SUI $0.6791 -1.39%
XLM $0.1585 -1.51%
ZEC $486.19 -1.98%

A high-risk vulnerability named "Cordyceps" has been exposed, affecting open-source repositories of major companies such as Microsoft and Google

2026-06-25 14:51:53

The Chief Information Security Officer of Slow Fog, 23pds, stated that researchers have exposed a high-risk vulnerability in CI/CD called Cordyceps, affecting the open-source repositories of major companies such as Microsoft, Google, Apache, and Cloudflare. Attackers do not need corporate accounts or any system permissions; they can simply register a free GitHub account, submit a malicious PR, and leave a comment to forge approvals, steal server keys, and push malicious code, completely taking control of the corporate code repository.

app_icon
ChainCatcher Building the Web3 world with innovations.