掃碼下載
BTC $60,080.47 -0.34%
ETH $1,574.73 -0.39%
BNB $554.45 -1.58%
XRP $1.04 -0.89%
SOL $71.34 -0.73%
TRX $0.3226 +0.64%
DOGE $0.0733 -2.44%
ADA $0.1445 -1.75%
BCH $192.39 -2.28%
LINK $7.24 -1.64%
HYPE $62.62 -0.85%
AAVE $89.07 -7.39%
SUI $0.6837 -2.35%
XLM $0.1709 -2.50%
ZEC $383.58 -5.93%
BTC $60,080.47 -0.34%
ETH $1,574.73 -0.39%
BNB $554.45 -1.58%
XRP $1.04 -0.89%
SOL $71.34 -0.73%
TRX $0.3226 +0.64%
DOGE $0.0733 -2.44%
ADA $0.1445 -1.75%
BCH $192.39 -2.28%
LINK $7.24 -1.64%
HYPE $62.62 -0.85%
AAVE $89.07 -7.39%
SUI $0.6837 -2.35%
XLM $0.1709 -2.50%
ZEC $383.58 -5.93%

名為 “Cordyceps” 的 CI/CD 高危漏洞曝光,微軟、谷歌等多個頭部企業開源倉庫中招

2026-06-25 14:51:53
收藏

ChainCatcher 消息,慢霧首席信息安全官 23pds 發文稱,研究員曝光了一類名為 Cordyceps 的 CI/CD 高危風險,微軟、谷歌、Apache、Cloudflare 等頭部企業的開源倉庫全都實測中招。攻擊者不用企業帳號、不用任何系統權限,僅註冊一個免費 GitHub 帳號,提交一段惡意 PR、留一條評論,就能偽造審批、偷取伺服器密鑰、推送惡意代碼,完全掌控企業代碼倉庫。

app_icon
ChainCatcher 與創新者共建Web3世界