Hackers Abuse GitHub Actions to Steal SSH Keys, Cloud Credentials and Access Tokens

Hackers are abusing GitHub Actions to steal SSH keys, cloud credentials, and access tokens through malicious workflows disguised as security checks. The workflows targeted 2,577 secrets, but targeting did not always translate into theft. Researchers confirmed successful exfiltration of 26 secrets from 13 repositories, highlighting the distinction between malicious injections and executed payloads. Attackers inserted […]

This article has been indexed from GBHackers Security | #1 Globally Trusted Cyber Security News Platform

Read the original article: