(评论)
(comments)

原始链接: https://news.ycombinator.com/item?id=43691339

Hacker News 最新 | 过去 | 评论 | 提问 | 展示 | 招聘 | 提交 登录 GitHub遭受级联式供应链攻击,CI/CD密钥泄露 (infoworld.com) vinnyglennon 29分钟前 22分 | 隐藏 | 过去 | 收藏 | 2条评论 chuckadams 1分钟前 | 下一条 [–] 这次攻击被描述为“复杂”的,但我们应该感谢(GitHub)之星,这次数据泄露是一次马虎的工作,最终只让公共仓库受到了影响。这几乎就像一个灰帽黑客试图让供应链漏洞更明显,而没有造成实际损害。 回复 apimade 16分钟前 | 上一条 [–] 之前的讨论:https://news.ycombinator.com/item?id=43368870 回复 加入我们,参加6月16日至17日在旧金山举办的AI创业学校! 指南 | 常见问题 | 列表 | API | 安全 | 法律 | 申请YC | 联系我们 搜索:


原文
Hacker News new | past | comments | ask | show | jobs | submit login
GitHub suffers a cascading supply chain attack compromising CI/CD secrets (infoworld.com)
22 points by vinnyglennon 29 minutes ago | hide | past | favorite | 2 comments










The attack is being described as “sophisticated” but we can thank our (GitHub) stars that the exfil was a half-assed job that ultimately made only public repos vulnerable. It’s almost like a grey-hat attacker trying to make the supply chain vulnerabilities more visible without doing actual damage.








Join us for AI Startup School this June 16-17 in San Francisco!


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact



Search:
联系我们 contact @ memedata.com