• About TC
  • Affiliate Disclaimer
  • Privacy Policy
  • TOS
  • Contact
Wednesday, May 14, 2025
Techcratic
Click For A Secret Deal
  • TC
  • AI
    Artificial Intelligence

    StreamBridge: Turning Your Offline Video Large Language Model into a Proactive Streaming Assistant

    Artificial Intelligence

    3 Excellent Practical Generative AI Courses

    Artificial Intelligence

    Building End-to-End Data Pipelines with Dask

    Artificial Intelligence

    Automate document translation and standardization with Amazon Bedrock and Amazon Translate

    Artificial Intelligence

    InterVision accelerates AI development using AWS LLM League and Amazon SageMaker AI

    Artificial Intelligence

    FireDucks: An Accelerated Fully Compatible Pandas Library

    Artificial Intelligence

    Breaking Out of Beginner: Python Patterns for Intermediate Data Scientists

    Artificial Intelligence

    Building a Personal Knowledge Management Tool with Reor

    Artificial Intelligence

    Build a location-aware agent using Amazon Bedrock Agents and Foursquare APIs

  • Crypto
    Bitcoin breakout to $120K on radar as markets forget Fed July rate cut

    Bitcoin breakout to $120K on radar as markets forget Fed July rate cut

    JPMorgan’s Kinexys, Chainlink, Ondo Finance Demo Atomic DvP Settlement for Real-World Assets

    JPMorgan’s Kinexys, Chainlink, Ondo Finance Demo Atomic DvP Settlement for Real-World Assets

    GFO-X Launches UK Regulated Trading Venue for Centrally Cleared Crypto Derivatives

    GFO-X Launches UK Regulated Trading Venue for Centrally Cleared Crypto Derivatives

    Bitcoin miners halt sales as BTC gains 20% since hash ribbon ‘buy’ signal

    Bitcoin miners halt sales as BTC gains 20% since hash ribbon ‘buy’ signal

    Solana Co-Founder Anatoly Yakovenko Floats Meta-Blockchain Proposal

    Solana Co-Founder Anatoly Yakovenko Floats Meta-Blockchain Proposal

    Hashdex Seeks SEC Approval to Add Litecoin to Crypto Index ETF

    South Korea’s Crypto Committee: Redefining Regulation?

    SEC Chair Discusses 3 Crypto Areas of Focus—Major Policy Moves Ahead

    SEC Chair Discusses 3 Crypto Areas of Focus—Major Policy Moves Ahead

    Market volatility indicator still points to $135K Bitcoin within 100 days — Analyst

    Market volatility indicator still points to $135K Bitcoin within 100 days — Analyst

    Best Presales to Buy Today – Which Coins Are Poised for a Breakout?

    $BEST Wallet Raises $12.2M as Altcoin Season Looms

  • Cybersecurity
    Cybersecurity

    Ivanti Patches EPMM Vulnerabilities Exploited for Remote Code Execution in Limited Attacks

    Cybersecurity

    Fortinet Patches CVE-2025-32756 Zero-Day RCE Flaw Exploited in FortiVoice Systems

    Cybersecurity

    Can we counter online disinformation?

    Cybersecurity

    Malicious PyPI Package Posing as Solana Tool Stole Source Code in 761 Downloads

    Cybersecurity

    China-Linked APTs Exploit SAP CVE-2025-31324 to Breach 581 Critical Systems Worldwide

    Cybersecurity

    Why Exposed Credentials Remain Unfixed—and How to Change That

    Cybersecurity

    Google Pays $1.375 Billion to Texas Over Unauthorized Tracking and Biometric Data Collection

    Cybersecurity

    Deploying AI Agents? Learn to Secure Them Before Hackers Strike Your Business

    Cybersecurity

    Google Rolls Out On-Device AI Protections to Detect Scams in Chrome and Android

  • Deals
    Forza Horizon 2 for Xbox 360 (Renewed)

    Forza Horizon 2 for Xbox 360 (Renewed)

    Little Big Planet – Playstation 3 (Renewed)

    Little Big Planet – Playstation 3 (Renewed)

    JCHPINE Hard Carrying Case for Leapfrog LeapLand Adventures Learning Video Game,…

    JCHPINE Hard Carrying Case for Leapfrog LeapLand Adventures Learning Video Game,…

    The Memory Company | Licensed NFL Team Logo Leather Flask with Shot Glass and Funnel Set

    The Memory Company | Licensed NFL Team Logo Leather Flask with Shot Glass and Funnel Set

    ORICO Portable SSD 256 GB with 2 in 1 USB C Cable, External Solid State Drives, Up to…

    ORICO Portable SSD 256 GB with 2 in 1 USB C Cable, External Solid State Drives, Up to…

    Lenovo ThinkPad T490s 14.0” FHD Laptop, Intel Quad-Core i7-8665U up to 3.90GHz, 32GB…

    Lenovo ThinkPad T490s 14.0” FHD Laptop, Intel Quad-Core i7-8665U up to 3.90GHz, 32GB…

    ICY DOCK 4 Bays Dual 2 x 2.5 inch Hard Drive SSD Mounting Bracket Adapter for External…

    ICY DOCK 4 Bays Dual 2 x 2.5 inch Hard Drive SSD Mounting Bracket Adapter for External…

    MINIX Z100-0dB Fanless Mini PC, Intel 12th Gen N100, 16GB DDR4/512GB PCIe 3.0 X4 SSD/4K…

    MINIX Z100-0dB Fanless Mini PC, Intel 12th Gen N100, 16GB DDR4/512GB PCIe 3.0 X4 SSD/4K…

    Crystal Clear Cover Kickstand Case for Steam Deck Gaming Console PC Protective Skin Case…

    Crystal Clear Cover Kickstand Case for Steam Deck Gaming Console PC Protective Skin Case…

  • Gaming
    First Look:  HYPERCHARGE: Unboxed

    First Look: HYPERCHARGE: Unboxed

    Scars Above Trailer Recensione Italiano

    Scars Above Trailer Recensione Italiano

    The Steam Deck Elden Ring Experience

    The Steam Deck Elden Ring Experience

    If you’re into ambient rainfaill sounds, why not use headphones with ‘two half-gallon basins’ and plenty of real water sloshing around everywhere

    If you’re into ambient rainfaill sounds, why not use headphones with ‘two half-gallon basins’ and plenty of real water sloshing around everywhere

    CORYXKENSHINNN!!!!!!!|FNAF MOVIE TRAILER REACTION FT @adtloud

    CORYXKENSHINNN!!!!!!!|FNAF MOVIE TRAILER REACTION FT @adtloud

    Gore Analysis – Robocop: Rogue City

    Gore Analysis – Robocop: Rogue City

    Thymesia – Walkthrough – Part 4 – Sea of Trees – Sub Quest 1

    Thymesia – Walkthrough – Part 4 – Sea of Trees – Sub Quest 1

    The latest Nvidia driver lets you run ancient CPUs in Windows again without crashing

    The latest Nvidia driver lets you run ancient CPUs in Windows again without crashing

    As Dusk Falls – Chapter 5 – Episode 37 Replayed So Even Sharon Goes To Jail

    As Dusk Falls – Chapter 5 – Episode 37 Replayed So Even Sharon Goes To Jail

  • Tesla
    Tesla (TSLA) board explore new pay deal for Elon Musk

    Tesla (TSLA) board explore new pay deal for Elon Musk

    KKTR-CAR Door Handle Cover, Real Matte Carbon Fiber Door Handle Trim Protector Set…

    KKTR-CAR Door Handle Cover, Real Matte Carbon Fiber Door Handle Trim Protector Set…

    Floor Mat for Tesla Model 3 2024 2025, Pure TPE Injection Molding All Weather Odorless…

    Floor Mat for Tesla Model 3 2024 2025, Pure TPE Injection Molding All Weather Odorless…

    Anti-Skid Center Console Silicone Pad for Tesla Model 3 Model Y 2020-2023, Wireless…

    Anti-Skid Center Console Silicone Pad for Tesla Model 3 Model Y 2020-2023, Wireless…

    Ziciner Car Registration Insurance Holder, 2Pack Essential Auto Card Document Glove Box…

    Ziciner Car Registration Insurance Holder, 2Pack Essential Auto Card Document Glove Box…

    MeeFar Hitch Mount Cargo Carrier Bag Soft Shell 100% Waterproof 20 Cubic Feet (59″ 24″…

    MeeFar Hitch Mount Cargo Carrier Bag Soft Shell 100% Waterproof 20 Cubic Feet (59″ 24″…

    Car Front Under Seat Storage Box for Tesla Model Y Model X 2020-2024 2025 Accessories…

    Car Front Under Seat Storage Box for Tesla Model Y Model X 2020-2024 2025 Accessories…

    Tesla employees try to oust Elon, new Volvo, and Micah’s close call

    Tesla employees try to oust Elon, new Volvo, and Micah’s close call

    Tesla shares video of its Optimus robot catching up to competition

    Tesla shares video of its Optimus robot catching up to competition

  • UFO
    Flexcamo -Tactical Waterproof Pants Tactical Pant for Men Relaxed Fit Work Camo Hiking Cargo Pants Multi Pockets

    Flexcamo -Tactical Waterproof Pants Tactical Pant for Men Relaxed Fit Work Camo Hiking Cargo Pants Multi Pockets

    Vanishing UFOs Spotted During WWII (Season 21) | Ancient Aliens

    Vanishing UFOs Spotted During WWII (Season 21) | Ancient Aliens

    Men’s Swim Trunks Beach Board Shorts Quick Dry Swimsuit Bathing Suits with Pockets 7 Inch Inseam Mesh Lining

    Men’s Swim Trunks Beach Board Shorts Quick Dry Swimsuit Bathing Suits with Pockets 7 Inch Inseam Mesh Lining

    Galaxy Space Alien Inflate | 3 Feet | One Pc | UFO Blow Up Decoration Toy

    Galaxy Space Alien Inflate | 3 Feet | One Pc | UFO Blow Up Decoration Toy

    Extraterrestrial Theory  by Goatrax   Official Report Video HD Micro Scan  08.05.2015   Concorde Atl

    Extraterrestrial Theory by Goatrax Official Report Video HD Micro Scan 08.05.2015 Concorde Atl

    Photographic Proof or Hoaxes? UFO Images Under the Microscope

    Photographic Proof or Hoaxes? UFO Images Under the Microscope

    Nicetage Women Vintage Space Shuttle Graphic T-Shirt NASA Letter Print Shirt Casual Tee Tops

    Nicetage Women Vintage Space Shuttle Graphic T-Shirt NASA Letter Print Shirt Casual Tee Tops

    U.S. Senator's amendment into UFO investigations gains momentum

    U.S. Senator's amendment into UFO investigations gains momentum

    Scooby-Doo:Alien Inv/SD:Zombie Is (DBFE)

    Scooby-Doo:Alien Inv/SD:Zombie Is (DBFE)

No Result
View All Result
  • TC
  • AI
    Artificial Intelligence

    StreamBridge: Turning Your Offline Video Large Language Model into a Proactive Streaming Assistant

    Artificial Intelligence

    3 Excellent Practical Generative AI Courses

    Artificial Intelligence

    Building End-to-End Data Pipelines with Dask

    Artificial Intelligence

    Automate document translation and standardization with Amazon Bedrock and Amazon Translate

    Artificial Intelligence

    InterVision accelerates AI development using AWS LLM League and Amazon SageMaker AI

    Artificial Intelligence

    FireDucks: An Accelerated Fully Compatible Pandas Library

    Artificial Intelligence

    Breaking Out of Beginner: Python Patterns for Intermediate Data Scientists

    Artificial Intelligence

    Building a Personal Knowledge Management Tool with Reor

    Artificial Intelligence

    Build a location-aware agent using Amazon Bedrock Agents and Foursquare APIs

  • Crypto
    Bitcoin breakout to $120K on radar as markets forget Fed July rate cut

    Bitcoin breakout to $120K on radar as markets forget Fed July rate cut

    JPMorgan’s Kinexys, Chainlink, Ondo Finance Demo Atomic DvP Settlement for Real-World Assets

    JPMorgan’s Kinexys, Chainlink, Ondo Finance Demo Atomic DvP Settlement for Real-World Assets

    GFO-X Launches UK Regulated Trading Venue for Centrally Cleared Crypto Derivatives

    GFO-X Launches UK Regulated Trading Venue for Centrally Cleared Crypto Derivatives

    Bitcoin miners halt sales as BTC gains 20% since hash ribbon ‘buy’ signal

    Bitcoin miners halt sales as BTC gains 20% since hash ribbon ‘buy’ signal

    Solana Co-Founder Anatoly Yakovenko Floats Meta-Blockchain Proposal

    Solana Co-Founder Anatoly Yakovenko Floats Meta-Blockchain Proposal

    Hashdex Seeks SEC Approval to Add Litecoin to Crypto Index ETF

    South Korea’s Crypto Committee: Redefining Regulation?

    SEC Chair Discusses 3 Crypto Areas of Focus—Major Policy Moves Ahead

    SEC Chair Discusses 3 Crypto Areas of Focus—Major Policy Moves Ahead

    Market volatility indicator still points to $135K Bitcoin within 100 days — Analyst

    Market volatility indicator still points to $135K Bitcoin within 100 days — Analyst

    Best Presales to Buy Today – Which Coins Are Poised for a Breakout?

    $BEST Wallet Raises $12.2M as Altcoin Season Looms

  • Cybersecurity
    Cybersecurity

    Ivanti Patches EPMM Vulnerabilities Exploited for Remote Code Execution in Limited Attacks

    Cybersecurity

    Fortinet Patches CVE-2025-32756 Zero-Day RCE Flaw Exploited in FortiVoice Systems

    Cybersecurity

    Can we counter online disinformation?

    Cybersecurity

    Malicious PyPI Package Posing as Solana Tool Stole Source Code in 761 Downloads

    Cybersecurity

    China-Linked APTs Exploit SAP CVE-2025-31324 to Breach 581 Critical Systems Worldwide

    Cybersecurity

    Why Exposed Credentials Remain Unfixed—and How to Change That

    Cybersecurity

    Google Pays $1.375 Billion to Texas Over Unauthorized Tracking and Biometric Data Collection

    Cybersecurity

    Deploying AI Agents? Learn to Secure Them Before Hackers Strike Your Business

    Cybersecurity

    Google Rolls Out On-Device AI Protections to Detect Scams in Chrome and Android

  • Deals
    Forza Horizon 2 for Xbox 360 (Renewed)

    Forza Horizon 2 for Xbox 360 (Renewed)

    Little Big Planet – Playstation 3 (Renewed)

    Little Big Planet – Playstation 3 (Renewed)

    JCHPINE Hard Carrying Case for Leapfrog LeapLand Adventures Learning Video Game,…

    JCHPINE Hard Carrying Case for Leapfrog LeapLand Adventures Learning Video Game,…

    The Memory Company | Licensed NFL Team Logo Leather Flask with Shot Glass and Funnel Set

    The Memory Company | Licensed NFL Team Logo Leather Flask with Shot Glass and Funnel Set

    ORICO Portable SSD 256 GB with 2 in 1 USB C Cable, External Solid State Drives, Up to…

    ORICO Portable SSD 256 GB with 2 in 1 USB C Cable, External Solid State Drives, Up to…

    Lenovo ThinkPad T490s 14.0” FHD Laptop, Intel Quad-Core i7-8665U up to 3.90GHz, 32GB…

    Lenovo ThinkPad T490s 14.0” FHD Laptop, Intel Quad-Core i7-8665U up to 3.90GHz, 32GB…

    ICY DOCK 4 Bays Dual 2 x 2.5 inch Hard Drive SSD Mounting Bracket Adapter for External…

    ICY DOCK 4 Bays Dual 2 x 2.5 inch Hard Drive SSD Mounting Bracket Adapter for External…

    MINIX Z100-0dB Fanless Mini PC, Intel 12th Gen N100, 16GB DDR4/512GB PCIe 3.0 X4 SSD/4K…

    MINIX Z100-0dB Fanless Mini PC, Intel 12th Gen N100, 16GB DDR4/512GB PCIe 3.0 X4 SSD/4K…

    Crystal Clear Cover Kickstand Case for Steam Deck Gaming Console PC Protective Skin Case…

    Crystal Clear Cover Kickstand Case for Steam Deck Gaming Console PC Protective Skin Case…

  • Gaming
    First Look:  HYPERCHARGE: Unboxed

    First Look: HYPERCHARGE: Unboxed

    Scars Above Trailer Recensione Italiano

    Scars Above Trailer Recensione Italiano

    The Steam Deck Elden Ring Experience

    The Steam Deck Elden Ring Experience

    If you’re into ambient rainfaill sounds, why not use headphones with ‘two half-gallon basins’ and plenty of real water sloshing around everywhere

    If you’re into ambient rainfaill sounds, why not use headphones with ‘two half-gallon basins’ and plenty of real water sloshing around everywhere

    CORYXKENSHINNN!!!!!!!|FNAF MOVIE TRAILER REACTION FT @adtloud

    CORYXKENSHINNN!!!!!!!|FNAF MOVIE TRAILER REACTION FT @adtloud

    Gore Analysis – Robocop: Rogue City

    Gore Analysis – Robocop: Rogue City

    Thymesia – Walkthrough – Part 4 – Sea of Trees – Sub Quest 1

    Thymesia – Walkthrough – Part 4 – Sea of Trees – Sub Quest 1

    The latest Nvidia driver lets you run ancient CPUs in Windows again without crashing

    The latest Nvidia driver lets you run ancient CPUs in Windows again without crashing

    As Dusk Falls – Chapter 5 – Episode 37 Replayed So Even Sharon Goes To Jail

    As Dusk Falls – Chapter 5 – Episode 37 Replayed So Even Sharon Goes To Jail

  • Tesla
    Tesla (TSLA) board explore new pay deal for Elon Musk

    Tesla (TSLA) board explore new pay deal for Elon Musk

    KKTR-CAR Door Handle Cover, Real Matte Carbon Fiber Door Handle Trim Protector Set…

    KKTR-CAR Door Handle Cover, Real Matte Carbon Fiber Door Handle Trim Protector Set…

    Floor Mat for Tesla Model 3 2024 2025, Pure TPE Injection Molding All Weather Odorless…

    Floor Mat for Tesla Model 3 2024 2025, Pure TPE Injection Molding All Weather Odorless…

    Anti-Skid Center Console Silicone Pad for Tesla Model 3 Model Y 2020-2023, Wireless…

    Anti-Skid Center Console Silicone Pad for Tesla Model 3 Model Y 2020-2023, Wireless…

    Ziciner Car Registration Insurance Holder, 2Pack Essential Auto Card Document Glove Box…

    Ziciner Car Registration Insurance Holder, 2Pack Essential Auto Card Document Glove Box…

    MeeFar Hitch Mount Cargo Carrier Bag Soft Shell 100% Waterproof 20 Cubic Feet (59″ 24″…

    MeeFar Hitch Mount Cargo Carrier Bag Soft Shell 100% Waterproof 20 Cubic Feet (59″ 24″…

    Car Front Under Seat Storage Box for Tesla Model Y Model X 2020-2024 2025 Accessories…

    Car Front Under Seat Storage Box for Tesla Model Y Model X 2020-2024 2025 Accessories…

    Tesla employees try to oust Elon, new Volvo, and Micah’s close call

    Tesla employees try to oust Elon, new Volvo, and Micah’s close call

    Tesla shares video of its Optimus robot catching up to competition

    Tesla shares video of its Optimus robot catching up to competition

  • UFO
    Flexcamo -Tactical Waterproof Pants Tactical Pant for Men Relaxed Fit Work Camo Hiking Cargo Pants Multi Pockets

    Flexcamo -Tactical Waterproof Pants Tactical Pant for Men Relaxed Fit Work Camo Hiking Cargo Pants Multi Pockets

    Vanishing UFOs Spotted During WWII (Season 21) | Ancient Aliens

    Vanishing UFOs Spotted During WWII (Season 21) | Ancient Aliens

    Men’s Swim Trunks Beach Board Shorts Quick Dry Swimsuit Bathing Suits with Pockets 7 Inch Inseam Mesh Lining

    Men’s Swim Trunks Beach Board Shorts Quick Dry Swimsuit Bathing Suits with Pockets 7 Inch Inseam Mesh Lining

    Galaxy Space Alien Inflate | 3 Feet | One Pc | UFO Blow Up Decoration Toy

    Galaxy Space Alien Inflate | 3 Feet | One Pc | UFO Blow Up Decoration Toy

    Extraterrestrial Theory  by Goatrax   Official Report Video HD Micro Scan  08.05.2015   Concorde Atl

    Extraterrestrial Theory by Goatrax Official Report Video HD Micro Scan 08.05.2015 Concorde Atl

    Photographic Proof or Hoaxes? UFO Images Under the Microscope

    Photographic Proof or Hoaxes? UFO Images Under the Microscope

    Nicetage Women Vintage Space Shuttle Graphic T-Shirt NASA Letter Print Shirt Casual Tee Tops

    Nicetage Women Vintage Space Shuttle Graphic T-Shirt NASA Letter Print Shirt Casual Tee Tops

    U.S. Senator's amendment into UFO investigations gains momentum

    U.S. Senator's amendment into UFO investigations gains momentum

    Scooby-Doo:Alien Inv/SD:Zombie Is (DBFE)

    Scooby-Doo:Alien Inv/SD:Zombie Is (DBFE)

No Result
View All Result
Techcratic
No Result
View All Result

GitHub Supply Chain Attack Enables Code Execution

Hacker News by Hacker News
March 27, 2025
in Hacker News
Reading Time: 8 mins read
121 9
A A
0
Home Hacker News
Share on FacebookShare on XShare on LinkedIn

Divya
2025-03-27 02:56:00
gbhackers.com

A recent discovery has revealed a potential supply chain attack vulnerability in GitHub’s CodeQL repositories, which could have led to wide-ranging consequences for hundreds of thousands of GitHub users.

The exploit hinges on a publicly exposed secret found in a GitHub Actions workflow artifact, which, if utilized by an attacker, could allow malicious code execution in multiple repositories.

Despite GitHub’s assertions that no compromise occurred, the severity of this vulnerability highlights the ongoing challenges in maintaining the security of continuous integration and continuous delivery (CI/CD) environments.

Background on CodeQL and GitHub Actions

CodeQL is GitHub’s powerful code analysis engine designed to identify vulnerabilities in repository code.

It has been instrumental in discovering several hundred CVEs, protecting organizations from potential breaches. However, this same critical role makes it an attractive target for attackers looking to exploit vulnerabilities.

GitHub Actions, on the other hand, is the platform’s CI/CD tool. It automates workflows for building, testing, and deploying code across repositories.

These workflows often rely on tokens like the GITHUB_TOKEN to authenticate and interact with GitHub. Tokens with high privileges pose significant risks if compromised.

GitHub App token installation token stored in a file containing the environment variables of the GitHub Runner executing the workflowGitHub App token installation token stored in a file containing the environment variables of the GitHub Runner executing the workflow
GitHub App token installation token stored in a file containing the environment variables of the GitHub Runner executing the workflow

The Vulnerability: “CodeQLEAKED”

In January 2025, security researchers embarked on a project to explore potential vulnerabilities in GitHub Actions workflows.

The GitHub token had full write privilegesThe GitHub token had full write privileges
The GitHub token had full write privileges

This investigation used a custom-built Actions Artifact Secrets Scanner, which downloaded and scanned GitHub Actions artifacts for exposed secrets.

The scanner uncovered a GitHub App installation token buried within an artifact from the github/codeql-action repository. This token, although valid for only a short duration, had full write permissions.

The exposed secret posed a risk because it was stored in an artifact uploaded during a workflow job using the v4 artifact upload API.

This allowed potential attackers to retrieve the artifact and extract the token before the workflow job completed. The crux of the vulnerability was the race against time: attackers had about two seconds to exploit the token before it expired.

Proving the Vulnerability

To demonstrate the exploit’s potential, researchers created a Python script named artifact_racer.py.

This tool continuously monitored the github/codeql-action repository for specific workflows, downloaded associated artifacts when detected, extracted the GITHUB_TOKEN, and used it to create a new branch and push an empty file to the branch.

The successful execution of these actions within the two-second window confirmed that an attacker could indeed exploit the vulnerability for malicious purposes.

Proving the VulnerabilityProving the Vulnerability
Proving the Vulnerability

Impact of the Vulnerability

The implications of this vulnerability are far-reaching. If an attacker could manipulate the github/codeql-action repository by adding malicious code and tags, they could compromise hundreds of thousands of repositories that enable CodeQL.

malicious code and tagsmalicious code and tags
malicious code and tags

This could involve:

  1. Intellectual Property Exfiltration: Repositories using default CodeQL settings would execute malicious actions allowing attackers to access sensitive code.
  2. Supply Chain Attacks: By modifying tags used in CodeQL actions, attackers could inject malicious code into any dependency relying on these tags.
  3. GitHub Actions Secrets Compromise: With code execution capabilities, attackers could potentially exfiltrate sensitive secrets stored in GitHub Actions workflows.

The discovery was responsibly disclosed to GitHub, which investigated and acknowledged the vulnerability as CVE-2025-24362.

Despite no reported compromises, the situation highlights the importance of vigilant monitoring and secure practices in managing CI/CD environments.

The “CodeQLEAKED” incident underscores the challenges in securing complex software ecosystems like GitHub.

It emphasizes the need for robust secret management practices, timely vulnerability disclosure, and strict monitoring of workflow artifacts to prevent similar supply chain attacks.

As code repositories increasingly depend on automation tools like GitHub Actions and analysis engines like CodeQL, ensuring their integrity is crucial for protecting intellectual property and maintaining security across digital ecosystems.

Are you from SOC/DFIR Teams? – Analyse Malware, Phishing Incidents & get live Access with ANY.RUN -> Start Now for Free. 

Source Link


Keep your files stored safely and securely with the SanDisk 2TB Extreme Portable SSD. With over 69,505 ratings and an impressive 4.6 out of 5 stars, this product has been purchased over 8K+ times in the past month. At only $129.99, this Amazon’s Choice product is a must-have for secure file storage.

Help keep private content private with the included password protection featuring 256-bit AES hardware encryption. Order now for just $129.99 on Amazon!


Start your free Amazon Prime trial
today and unlock unlimited streaming and more!

Help Power Techcratic’s Future – Scan To Support

If Techcratic’s content and insights have helped you, consider giving back by supporting the platform with crypto. Every contribution makes a difference, whether it’s for high-quality content, server maintenance, or future updates. Techcratic is constantly evolving, and your support helps drive that progress.

As a solo operator who wears all the hats, creating content, managing the tech, and running the site, your support allows me to stay focused on delivering valuable resources. Your support keeps everything running smoothly and enables me to continue creating the content you love. I’m deeply grateful for your support, it truly means the world to me! Thank you!

BITCOIN

Bitcoin Logo

Bitcoin QR Code

bc1qlszw7elx2qahjwvaryh0tkgg8y68enw30gpvge

Scan the QR code with your crypto wallet app

DOGECOIN

Dogecoin Logo

Dogecoin QR Code

D64GwvvYQxFXYyan3oQCrmWfidf6T3JpBA

Scan the QR code with your crypto wallet app

ETHEREUM

Ethereum Logo

Ethereum QR Code

0xe9BC980DF3d985730dA827996B43E4A62CCBAA7a

Scan the QR code with your crypto wallet app

Please read the Privacy and Security Disclaimer on how Techcratic handles your support.

Disclaimer: As an Amazon Associate, Techcratic may earn from qualifying purchases.

Tags: Hacker News
Share162Tweet101Share28
Previous Post

Aliens Another Glorious Day In The Corps – Board Game Review (Plus Expansions)

Next Post

What is Fair in an AI-Enabled Workplace? Leaders Are Struggling to Answer This Question

Hacker News

Hacker News

Stay updated with Hacker News, where technology meets entrepreneurial spirit. Get the latest on tech trends, startup news, and discussions from the tech community. Read the latest updates here at Techcratic.

Related Posts

Unhappy with the recently lost file upload feature in the Nextcloud app for Android? So are we. Let us explain.
Hacker News

Unhappy with the recently lost file upload feature in the Nextcloud app for Android? So are we. Let us explain.

May 14, 2025
1.3k
Databricks and Neon | Databricks Blog
Hacker News

Databricks and Neon | Databricks Blog

May 14, 2025
1.3k
INE Security Alert: Continuous CVE Practice Closes Critical Gap Between Vulnerability Alerts and Effective Defense – Latest Hacking News
Hacker News

INE Security Alert: Continuous CVE Practice Closes Critical Gap Between Vulnerability Alerts and Effective Defense – Latest Hacking News

May 14, 2025
1.3k
You can use C-Reduce for any language
Hacker News

Writing that changed how I think about PL

May 14, 2025
1.3k
A tool to verify estimates, II: a flexible proof assistant
Hacker News

A tool to verify estimates, II: a flexible proof assistant

May 14, 2025
1.3k
Airbnb Is in Midlife Crisis Mode
Hacker News

Airbnb Is in Midlife Crisis Mode

May 13, 2025
1.3k
Load More
Next Post
What is Fair in an AI-Enabled Workplace? Leaders Are Struggling to Answer This Question

What is Fair in an AI-Enabled Workplace? Leaders Are Struggling to Answer This Question

2 HOUR JOB SEARCH

Network Architect - Hybrid

Les meilleurs logiciels pour faire du Pixel Art !

Les meilleurs logiciels pour faire du Pixel Art !

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Tech Resources

  • 30 Second Tech ™
  • AI
  • App Zone ™
  • Apple
  • Ars Technica
  • CNET
  • ComputerWorld
  • Crypto News
  • Cybersecurity
  • Endgadget
  • Fossbytes
  • Gaming
  • GeekWire
  • Gizmodo
  • Google News
  • Hacker News
  • Harvard Tech
  • I Like Cats ™
  • I Like Dogs ™
  • LifeHacker
  • MacRumors
  • Macworld
  • Mashable
  • Microsoft
  • MIT Tech
  • PC World
  • Photofocus
  • Physics
  • Random Tech
  • Retro Rewind ™
  • Robot Report
  • SiliconANGLE
  • SlashGear
  • Smartphone
  • StackSocial
  • Tech Art
  • Tech Careers
  • Tech Deals
  • Techcratic ™
  • TechCrunch
  • Techdirt
  • TechRepublic
  • Techs Got To Eat ™
  • TechSpot
  • Tesla
  • The Verge
  • TNW
  • Trusted Reviews
  • UFO
  • VentureBeat
  • Visual Capitalist
  • Weird Stuff
  • Wired
  • ZDNet

Tech News

  • 30 Second Tech ™
  • AI
  • AnandTech
  • Apple Insider
  • Ars Technica
  • CNET
  • ComputerWorld
  • Crypto News
  • Cybersecurity
  • Endgadget
  • ExtremeTech
  • Fossbytes
  • Gaming
  • GeekWire
  • Gizmodo

Tech News

  • Harvard Tech
  • MacRumors
  • Macworld
  • Mashable
  • Microsoft
  • MIT Tech
  • Physics
  • PC World
  • Random Tech
  • Retro Rewind ™
  • SiliconANGLE
  • SlashGear
  • Smartphone
  • StackSocial
  • Tech Careers

Tech News​

  • Tech Art
  • TechCrunch
  • Techdirt
  • TechRepublic
  • Techs Got To Eat ™
  • TechSpot
  • Tesla
  • The Verge
  • TNW
  • Trusted Reviews
  • UFO
  • VentureBeat
  • Visual Capitalist
  • Weird Stuff
  • Wired
  • ZDNet

Site Links

  • About Techcratic
  • Affiliate Disclaimer
  • Affiliate Link Policy
  • Contact Techcratic
  • Dealors Discount Store
  • Privacy and Security Disclaimer
  • Privacy Policy
  • RSS Feed
  • Site Map
  • Support Techcratic
  • Techcratic
  • Tech Deals
  • TOS
  • 𝕏
Click For A Secret Deal

Techcratic – Your All In One Tech Hub © 2020 – 2025
All Rights Reserved
∞

No Result
View All Result
  • Home
  • Apple
  • Gaming
  • Microsoft
  • AnandTech