Remove tag date-leak
article thumbnail

The GitHub Actions Worm: Compromising GitHub Repositories Through the Actions Dependency Tree

Prisma Clud

Get an in-depth look at the attack vectors, technical details and a real-world demo in this blog post highlighting our latest research. Reference a tag. Figure 8: Calling an action using a tag We can use the secrets exfiltrated in the flow to infect the repository with malicious code. Reference a commit hash. Reference a branch.

Malware 144
article thumbnail

Frequently Asked Questions for CitrixBleed (CVE-2023-4966)

Tenable

Background The Tenable Security Response Team has put together this blog to answer frequently Asked Questions (FAQ) regarding a critical vulnerability known as CitrixBleed. High We published a blog post for both vulnerabilities on October 18. FAQ What is CitrixBleed? What makes CitrixBleed so severe?

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

How Watchdog smuggles malware into your network as uninteresting photos

Lacework

This blog takes a look at the latter technique in recent cryptojacking activity from a group known as WatchDog. If true, this indicates that keys to the Alibaba OSS buckets used by WatchDog were leaked on Github and the buckets were subsequently recruited as unwitting malware hosts. This includes WatchDog steg payloads from this blog.

Malware 96
article thumbnail

Detect hardcoded secrets with GitGuardian

CircleCI

Leaked credentials aren’t just a security problem; rotating a leaked secret interrupts CI/CD workflows. The vast majority of leaked credentials are mistakes and do not spring from malicious intent. No secrets have been found commit 90220851160dcf018f372536da223dc0396aa247 Author: Date: CircleCI received exit code 0.

article thumbnail

Why The Health Care Reform Debate Makes Me Sick

The Recovering Engineer

A former co-worker of mine once received a call from a family member for help with a leaking water heater. As my co-worker entered his family member’s home, he found his brother-in-law frantically mopping water from the floor trying to stay ahead of the leaking water heater.

Video 41
article thumbnail

Why The Health Care Reform Debate Makes Me Sick

The Recovering Engineer

A former co-worker of mine once received a call from a family member for help with a leaking water heater. As my co-worker entered his family member’s home, he found his brother-in-law frantically mopping water from the floor trying to stay ahead of the leaking water heater.

Video 41
article thumbnail

Redesigning Our Docs – Part 4 – Building a Scalable CSS Architecture

Algolia

This is the fourth article in a seven-part series of blogs that describe our most recent changes to the architecture and content of our documentation. A simple change could turn into an hour of keeping duplicates up to date and battling media queries. Preventing style leaks. Smaller browser memory footprint.