www.darkreading.com 6/23/2026, 8:10:01 PM · external

Cordyceps flaw leaves CI/CD open to supply chain attack

Cordyceps flaw leaves CI/CD open to supply chain attack
CyberSIXT Evidence Panel
Primary Source novee.security

A new vulnerability known as 'Cordyceps' threatens CI/CD workflows by allowing attackers to exploit malicious pull requests to compromise software supply chains. The issue affects notable platforms including Microsoft's Azure Sentinel and Google's AI Agent Development Kit, with reports indicating that 654 repositories could potentially be exploited. Key points include:

1. The vulnerability lies in access permissions granted to pull requests, allowing unauthorized actions such as code execution and credential theft.

2. Novee, a security firm, confirmed 300 repositories are fully exploitable.

3. The threat enables significant issues like signature spoofing and the distribution of malicious code.

4. Recommendations for organizations include securing developer workflows by treating CI/CD workflows as sensitive code assets and auditing access permissions.

View Primary Source Via www.darkreading.com

Article by CyberSIXT