Scan to download
BTC $60,139.96 +0.98%
ETH $1,609.94 +2.51%
BNB $558.66 +1.44%
XRP $1.05 +1.20%
SOL $74.97 +5.17%
TRX $0.3209 -0.24%
DOGE $0.0732 +0.24%
ADA $0.1455 +1.39%
BCH $200.46 +5.04%
LINK $7.37 +1.52%
HYPE $66.83 +9.15%
AAVE $91.39 +0.42%
SUI $0.7018 +3.09%
XLM $0.1746 +1.20%
ZEC $407.04 +8.21%
BTC $60,139.96 +0.98%
ETH $1,609.94 +2.51%
BNB $558.66 +1.44%
XRP $1.05 +1.20%
SOL $74.97 +5.17%
TRX $0.3209 -0.24%
DOGE $0.0732 +0.24%
ADA $0.1455 +1.39%
BCH $200.46 +5.04%
LINK $7.37 +1.52%
HYPE $66.83 +9.15%
AAVE $91.39 +0.42%
SUI $0.7018 +3.09%
XLM $0.1746 +1.20%
ZEC $407.04 +8.21%

A high-risk vulnerability named "Cordyceps" has been exposed, affecting open-source repositories of major companies such as Microsoft and Google

2026-06-25 14:51:53
Collection

The Chief Information Security Officer of Slow Fog, 23pds, stated that researchers have exposed a high-risk vulnerability in CI/CD called Cordyceps, affecting the open-source repositories of major companies such as Microsoft, Google, Apache, and Cloudflare. Attackers do not need corporate accounts or any system permissions; they can simply register a free GitHub account, submit a malicious PR, and leave a comment to forge approvals, steal server keys, and push malicious code, completely taking control of the corporate code repository.

app_icon
ChainCatcher Building the Web3 world with innovations.