The GhostAction supply chain campaign has hit 772 public GitHub repositories belonging to 373 users and organizations, targeting 2,577 secrets stored in continuous integration and deployment pipelines. GitGuardian tracked the latest wave between August 31 and September 30, 2026, after Cynative researchers independently spotted malicious commits.... Weiterlesen: GhostAction Supply Chain Attack Hits 772 GitHub Repositories to Steal…
Intelligence View
⚡ tsecurity.de Intelligence
GhostAction Supply Chain Attack Hits 772 GitHub Repositories to Steal CI/CD Secrets
The GhostAction supply chain campaign has hit 772 public GitHub repositories belonging to 373 users and organizations, targeting 2,577 secrets stored in…
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!
🔍 CTI & Forensik
2
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege
CTI Threat Relationship Graph
Akteure · Techniken · Beziehungen
CVE / Incident Threat Actor Software MITRE ATT&CK CWE Weakness IoC
Powered by tsecurity.de
tsecurity.de Hub
Intelligence Digest — kostenlos Täglich die wichtigsten Security-News · jederzeit abbestellbar
Community Rating & Social Proof
⭐ Leser-Wertung
–
Ø / 5.0
★★★★★
Noch keine Leser-Bewertungen
War diese Seite hilfreich?
0
Powered by tsecurity.de
tsecurity.de Hub
Verwandte Story-Cluster & Quellen (Vektor-KI)
32 Quellen
CVE-2016-1000031 | Oracle Agile Engineering Data Management 6.2.0/6.2.1 Apache Commons FileUpload access control (Nessus ID 118732 / ID 316356)
31 weitere Quellen
VVulDB Updatesvor 5 Std.CVE-2016-1000031 | Oracle Database 12.2.0.1/18c/19c MapViewer access control (ID 316356 / BID-93604) VVulDB Updatesvor 5 Std.CVE-2016-1000031 | Oracle Insurance Policy Administration J2EE 10.0/10.1/10.2/11.0 Apache Commons FileUpload access control (Nessus ID 118732 / ID 316356) VVulDB Updatesvor 5 Std.CVE-2016-1000031 | Oracle Insurance Rules Palette 10.0/10.1/10.2/11.0 Apache Commons FileUpload access control (Nessus ID 118732 / ID 316356) VVulDB Updatesvor 5 Std.CVE-2016-1000031 | Oracle Insurance Calculation Engine 9.7/10.0/10.1/10.2 Apache Commons FileUpload access control (Nessus ID 118732 / ID 316356) VVulDB Updatesvor 5 Std.CVE-2016-1000031 | Oracle Knowledge up to 8.6.3 Information Manager Console/Web Applications access control (ID 316356 / BID-93604) VVulDB Updatesvor 5 Std.CVE-2016-1000031 | Oracle Business Intelligence Enterprise Edition 11.1.1.9.0/12.2.1.3.0/12.2.1.4.0 BI Platform Security access control (ID 316356 / BID-93604)
+25
22 Quellen
GitHub Release: NousResearch/hermes-agent vrc.2-v0.21.6 (08.10.2026)
21 weitere Quellen
GGitHubvor 32 Min.GitHub Release: openai/codex vrust-v0.162.0-alpha.17.2 (08.10.2026) GGitHubvor 1 Std.GitHub Release: anthropics/claude-code v2.1.294 (08.10.2026) GGitHubvor 1 Std.GitHub Release: cline/cline vsdk/shared/v0.0.92 (08.10.2026) GGitHubvor 1 Std.GitHub Release: cline/cline vsdk/llms/v0.0.92 (08.10.2026) GGitHubvor 1 Std.GitHub Release: cline/cline vsdk/agents/v0.0.92 (08.10.2026) GGitHubvor 1 Std.GitHub Release: cline/cline vsdk/core/v0.0.92 (08.10.2026)
+15
8 Quellen
Weltraumwoche 2026: Dieses Foto seht ihr heute auf der Google-Startseite – ein Doodle zur Feier des Weltraums
7 weitere Quellen
GGoogleWatchBlogvor 25 Min.Google Wallet: Neue Startseite mit Bezahlkarten-Stapel wird jetzt ausgerollt – erleichtert Auswahl (Screenshots) VVulDB Updatesvor 2 Std.CVE-2026-56906 | Google Android eventpoll eventpoll.c ep_free use after free (WID-SEC-2026-3786) VVulDB Updatesvor 2 Std.CVE-2026-56936 | Google Android Wacom HID Driver wacom_sys.c wacom_hid_set_device_mode out-of-bounds write (WID-SEC-2026-3786) VVulDB Updatesvor 2 Std.CVE-2026-56952 | Google Android default_msg_handlers.c platform_msg_handler_init permission (WID-SEC-2026-3786) VVulDB Updatesvor 3 Std.CVE-2026-0198 | Google Android Permission Check gem_msg.c is_pd_allowed permission (WID-SEC-2026-3786) VVulDB Updatesvor 3 Std.CVE-2026-55307 | Google Android hwcrypto hwcrypto-kdn.c kdn_set_sysregs_prot information disclosure (WID-SEC-2026-3786)
+1
Mehr aus dieser Kategorie
Blättern: Pfeiltasten [ ← ] [ → ] · Tasten j / k · mobil: Wischen
HAND-OFF
Auf Smartphone übergeben (ADVISORY)
Scannen Sie den QR-Code mit der Smartphone-Kamera für sofortigen mobilen Zugriff:
https://tsecurity.de/de/4248176/sichere-programmierung/ghostaction-supply-chain-attack-hits-772-github-repositories-to-steal-cicd-secrets/