<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic GitHub Attack Vector Cracks Open Google, Microsoft, AWS Projects in Threats</title>
    <link>https://community.isc2.org/t5/Threats/GitHub-Attack-Vector-Cracks-Open-Google-Microsoft-AWS-Projects/m-p/73249#M1355</link>
    <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cloud services and thus millions of end users who access them could have been affected by the poisoning of artifacts in the development workflow of open source projects.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Researchers have uncovered an attack vector that affected &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" href="https://www.darkreading.com/application-security/github-repos-targeted-in-cyber-extortion-attacks" target="_self"&gt;GitHub open source projects&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt; owned by Google, Microsoft, Amazon Web Services, and others, executed by abusing artifacts generated as part of software-development workflows.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Researchers at Palo Alto Networks' Unit 42 discovered the attack, which was effective against "high-profile open source projects owned by the biggest companies in the world," according to &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" href="https://unit42.paloaltonetworks.com/github-repo-artifacts-leak-tokens/" target="_blank" rel="noopener"&gt;a blog post&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt; published by lead researcher Yaron Avital yesterday. Compromise of those projects, then, "could have led to a potential impact on millions of their consumers."&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;A href="https://www.darkreading.com/cloud-security/github-attack-vector-google-microsoft-aws-projects" target="_blank" rel="noopener"&gt;https://www.darkreading.com/cloud-security/github-attack-vector-google-microsoft-aws-projects&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Caute_Cautim&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 19 Aug 2024 21:09:29 GMT</pubDate>
    <dc:creator>Caute_cautim</dc:creator>
    <dc:date>2024-08-19T21:09:29Z</dc:date>
    <item>
      <title>GitHub Attack Vector Cracks Open Google, Microsoft, AWS Projects</title>
      <link>https://community.isc2.org/t5/Threats/GitHub-Attack-Vector-Cracks-Open-Google-Microsoft-AWS-Projects/m-p/73249#M1355</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cloud services and thus millions of end users who access them could have been affected by the poisoning of artifacts in the development workflow of open source projects.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Researchers have uncovered an attack vector that affected &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" href="https://www.darkreading.com/application-security/github-repos-targeted-in-cyber-extortion-attacks" target="_self"&gt;GitHub open source projects&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt; owned by Google, Microsoft, Amazon Web Services, and others, executed by abusing artifacts generated as part of software-development workflows.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Researchers at Palo Alto Networks' Unit 42 discovered the attack, which was effective against "high-profile open source projects owned by the biggest companies in the world," according to &lt;/SPAN&gt;&lt;SPAN class=""&gt;&lt;A class="" href="https://unit42.paloaltonetworks.com/github-repo-artifacts-leak-tokens/" target="_blank" rel="noopener"&gt;a blog post&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN class=""&gt; published by lead researcher Yaron Avital yesterday. Compromise of those projects, then, "could have led to a potential impact on millions of their consumers."&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;&lt;A href="https://www.darkreading.com/cloud-security/github-attack-vector-google-microsoft-aws-projects" target="_blank" rel="noopener"&gt;https://www.darkreading.com/cloud-security/github-attack-vector-google-microsoft-aws-projects&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class=""&gt;Caute_Cautim&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;&lt;P class=""&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Aug 2024 21:09:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/GitHub-Attack-Vector-Cracks-Open-Google-Microsoft-AWS-Projects/m-p/73249#M1355</guid>
      <dc:creator>Caute_cautim</dc:creator>
      <dc:date>2024-08-19T21:09:29Z</dc:date>
    </item>
  </channel>
</rss>

