掃碼下載
BTC $77,399.92 +2.94%
ETH $2,429.30 +3.31%
BNB $641.54 +1.02%
XRP $1.48 +1.73%
SOL $89.19 -0.60%
TRX $0.3272 +0.30%
DOGE $0.1000 +1.48%
ADA $0.2610 +0.77%
BCH $454.75 +2.05%
LINK $9.66 +1.00%
HYPE $44.37 +1.53%
AAVE $117.25 +0.55%
SUI $1.01 +2.13%
XLM $0.1748 +4.42%
ZEC $328.05 -4.45%
BTC $77,399.92 +2.94%
ETH $2,429.30 +3.31%
BNB $641.54 +1.02%
XRP $1.48 +1.73%
SOL $89.19 -0.60%
TRX $0.3272 +0.30%
DOGE $0.1000 +1.48%
ADA $0.2610 +0.77%
BCH $454.75 +2.05%
LINK $9.66 +1.00%
HYPE $44.37 +1.53%
AAVE $117.25 +0.55%
SUI $1.01 +2.13%
XLM $0.1748 +4.42%
ZEC $328.05 -4.45%

慢霧餘弦:Coinbase 曾遭 GitHub Actions CI/CD 機制供應鏈攻擊,建議企業自查相關風險

2025-03-23 16:07:55
收藏

ChainCatcher 消息,慢霧餘弦在 X 平台發文稱,利用 GitHub Actions CI/CD 機制供應鏈攻擊 Coinbase,所幸沒有繼續成功,否則下一個被爆的安全事件就是針對 Coinbase 了。在 GitHub 上的供應鏈攻擊路徑:reviewdog/action-setup -> tj-actions/changed-files -> coinbase/agentkit ->竊取 GitHub Personal Access Token(PAT)、雲服務有關密鑰等。餘弦建議,如果企業用到 reviewdog 或 tj-actions,應該進行自查。

app_icon
ChainCatcher 與創新者共建Web3世界