Scan to download
BTC $60,080.47 -0.34%
ETH $1,574.73 -0.39%
BNB $554.45 -1.58%
XRP $1.04 -0.89%
SOL $71.34 -0.73%
TRX $0.3226 +0.64%
DOGE $0.0733 -2.44%
ADA $0.1445 -1.75%
BCH $192.39 -2.28%
LINK $7.24 -1.64%
HYPE $62.62 -0.85%
AAVE $89.07 -7.39%
SUI $0.6837 -2.35%
XLM $0.1709 -2.50%
ZEC $383.58 -5.93%
BTC $60,080.47 -0.34%
ETH $1,574.73 -0.39%
BNB $554.45 -1.58%
XRP $1.04 -0.89%
SOL $71.34 -0.73%
TRX $0.3226 +0.64%
DOGE $0.0733 -2.44%
ADA $0.1445 -1.75%
BCH $192.39 -2.28%
LINK $7.24 -1.64%
HYPE $62.62 -0.85%
AAVE $89.07 -7.39%
SUI $0.6837 -2.35%
XLM $0.1709 -2.50%
ZEC $383.58 -5.93%

A high-risk vulnerability named "Cordyceps" has been exposed, affecting open-source repositories of major companies such as Microsoft and Google

2026-06-25 14:51:53
Collection

The Chief Information Security Officer of Slow Fog, 23pds, stated that researchers have exposed a high-risk vulnerability in CI/CD called Cordyceps, affecting the open-source repositories of major companies such as Microsoft, Google, Apache, and Cloudflare. Attackers do not need corporate accounts or any system permissions; they can simply register a free GitHub account, submit a malicious PR, and leave a comment to forge approvals, steal server keys, and push malicious code, completely taking control of the corporate code repository.

app_icon
ChainCatcher Building the Web3 world with innovations.