Source: The Hacker News

GitHub: SpotBugs Access Token Theft Identified as Root Cause of GitHub Supply Chain Attack

The cascading supply chain attack that initially targeted Coinbase before becoming more widespread to single out users of the "tj-actions/changed-files" GitHub Action has been traced further back to the theft of a personal access token (PAT) related to SpotBugs. "The attackers obtained initial access by taking advantage of the GitHub Actions workflow of SpotBugs, a popular open-source tool for

Read full article »
Est. Annual Revenue
$1.0-5.0B
Est. Employees
1.0-5.0K
Thomas Dohmke's photo - CEO of GitHub

CEO

Thomas Dohmke

CEO Approval Rating

82/100

Read more