Hackers are abusing GitHub Actions to steal SSH keys, cloud credentials, and access tokens through malicious workflows disguised as security checks. The workflows targeted 2,577 secrets, but targeting did not always translate into theft. Researchers confirmed successful exfiltration of 26 secrets from 13 repositories, highlighting the distinction between malicious injections and executed payloads. Attackers inserted […]
Read the original article:
