A leaked GitHub token exposed internal build systems at two chipmakers
A token committed to a public repository gave read access to private repositories containing firmware signing workflows at two semiconductor companies for at least nine weeks.
Section
Threats, defenses, and the quiet work of keeping systems trustworthy.
12 articles
Loading…
A token committed to a public repository gave read access to private repositories containing firmware signing workflows at two semiconductor companies for at least nine weeks.
A bidirectional integration lets a suspicious sign-in trigger endpoint isolation and lets endpoint compromise revoke sessions, closing a gap attackers have exploited for years.
Access policies can now require a signed statement from a device's security chip proving disk encryption, secure boot, and OS version, which closes the gap agent-based posture checks left open.
A memory corruption bug in Zoom's screen sharing path allowed code execution on a participant's machine from a joined meeting. Attackers used it against firms working on cross-border litigation.
A cryptographic escrow scheme lets an organization restore an employee's passkeys after device loss without any party holding a usable copy of the private keys.
Extensions can no longer read cookies for sites the user is not actively visiting, which breaks a category of shopping, coupon, and analytics extensions built on cross-site tracking.
A team at Ruhr University Bochum showed that cache keys in GitHub Actions can be poisoned from a fork's pull request workflow, injecting artifacts into a main branch build.
GitHub will require signed build provenance for the roughly 3,100 npm packages with over a million weekly downloads, with a compliance deadline of March 2027.
An internal red team used abandoned application registrations to reach production data. Microsoft's response revoked 1,900 credentials and changed the default lifetime for new secrets.