Briefing

Cordyceps: New CI/CD Workflow Weakness Threatens Open-Source Supply Chains

security
by [email protected] (The Hacker News) ·

Patch CI/CD workflows to mitigate Cordyceps.

What to do now

Patch CI/CD configurations to restrict workflow permissions.

Summary

Novee Security identified a new class of CI/CD workflow weakness, codenamed Cordyceps, that allows attackers to hijack workflows and compromise open‑source supply chains.

The critical exploitable pattern gives full attacker control of repositories, affecting major organizations such as Microsoft, Google, and Apache.

Cordyceps requires no credentials or sign‑in, enabling seamless takeover of CI/CD pipelines.

The vulnerability threatens the integrity of open‑source projects and the security of downstream users.

Organizations must review workflow permissions and implement stricter controls.

The discovery underscores the need for robust CI/CD security practices.

Mitigation involves tightening access and monitoring for anomalous workflow activity.

Overall, Cordyceps represents a significant risk to the software supply chain.

Key changes

  • Cordyceps identified as a critical CI/CD workflow weakness.
  • Allows attackers to hijack workflows and gain full control of repositories.
  • Compromises open‑source supply chains for major organizations.
  • Affects Microsoft, Google, Apache, and others.
  • No credentials or sign‑in required for exploitation.
  • Requires tightening of workflow permissions and security controls.

Affects

internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting