Get all your news in one place.
100's of premium titles.
One app.
Start reading
TechRadar
TechRadar
Efosa Udinmwen

Jaw-dropping security flaws found in open source code could allow hackers to spirit away entire projects - here's what devs need to know

GitHub Actions found in MITRE, Splunk, and other open source repositories.

  • Sysdig exposed how a trusted GitHub feature can silently hand control to attackers
  • pull_request_target isn’t just risky, it’s a loaded weapon in the wrong hands
  • Even top-tier security projects like MITRE’s can fall to simple GitHub workflow misconfigurations
Sign up to read this article
Read news from 100's of titles, curated specifically for you.
Already a member? Sign in here
Related Stories
Top stories on inkl right now
One subscription that gives you access to news from hundreds of sites
Already a member? Sign in here
Our Picks
Fourteen days free
Download the app
One app. One membership.
100+ trusted global sources.