扫码下载
BTC $60,080.47 -0.34%
ETH $1,574.73 -0.39%
BNB $554.45 -1.58%
XRP $1.04 -0.89%
SOL $71.34 -0.73%
TRX $0.3226 +0.64%
DOGE $0.0733 -2.44%
ADA $0.1445 -1.75%
BCH $192.39 -2.28%
LINK $7.24 -1.64%
HYPE $62.62 -0.85%
AAVE $89.07 -7.39%
SUI $0.6837 -2.35%
XLM $0.1709 -2.50%
ZEC $383.58 -5.93%
BTC $60,080.47 -0.34%
ETH $1,574.73 -0.39%
BNB $554.45 -1.58%
XRP $1.04 -0.89%
SOL $71.34 -0.73%
TRX $0.3226 +0.64%
DOGE $0.0733 -2.44%
ADA $0.1445 -1.75%
BCH $192.39 -2.28%
LINK $7.24 -1.64%
HYPE $62.62 -0.85%
AAVE $89.07 -7.39%
SUI $0.6837 -2.35%
XLM $0.1709 -2.50%
ZEC $383.58 -5.93%

名为 “Cordyceps” 的 CI/CD 高危漏洞曝光,微软、谷歌等多个头部企业开源仓库中招

2026-06-25 14:51:53
收藏

ChainCatcher 消息,慢雾首席信息安全官 23pds 发文称,研究员曝光了一类名为 Cordyceps 的 CI/CD 高危风险,微软、谷歌、Apache、Cloudflare 等头部企业的开源仓库全都实测中招。攻击者不用企业账号、不用任何系统权限,仅注册一个免费 GitHub 账号,提交一段恶意 PR、留一条评论,就能伪造审批、偷取服务器密钥、推送恶意代码,完全掌控企业代码仓库。

app_icon
ChainCatcher 与创新者共建Web3世界