Researchers have uncovered hundreds of GitHub users and repositories impacted by a supply chain attack in which hackers stole more than 3,325 secrets.
You can read more details here: https://blog.gitguardian.com/ghostaction-campaign-3-325-secrets-stolen/
Jim Routh, Chief Trust Officer at AI-based identity security and governance solutions provider Saviynt, commented:
“This incident provides cyber professionals with an excellent example of how malicious threat actors can operate at scale by using compromised credentials for accounts that are part of the software supply chain. It is an extended attack surface for cyber criminals given the fundamental changes to software assembly using essential cloud accounts.
“These types of incidents will (unfortunately) continue until enterprises figure out that identity security is essential when establishing and managing all accounts. That means that your IAM practices must be applied when setting up, configuring cloud and managing (SaaS) accounts and not leaving it for your software engineers to figure out. The large scale use of tokens by cloud providers offers convenience in authentication which is positive, but extends the attack surface when credentials are easily compromised.
“Identity security today (and tomorrow) means the application of identity management for the full lifecycle across all types of human and non-human accounts. This starts with ways to identify existing accounts, create a data lake for them and their uses, and uniformly apply identity access management across all enterprise accounts. The majority of enterprises today apply identity security capabilities for accounts provisioned by the operations team but not the engineering teams who need cloud access to assemble software. Until this changes, we will see more cases of compromised credentials used by threat actors impacting the software supply chain.
“Cloud accounts set up for software engineers represent privileged accounts where privileges need more real time protections. This is the next generation of privileged access management (PAM) to reduce the use of compromised credentials.”
Supply chain attacks are all the rage right now. Organizations need to take action to ensure that they are not victims of a supply chain attack by doing everything possible to minimize their risk. And I do mean everything possible.
Related
This entry was posted on September 9, 2025 at 10:37 am and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
GhostAction Supply Chain Attack Compromises 3,225 Secrets Via GitHub Workflows
Researchers have uncovered hundreds of GitHub users and repositories impacted by a supply chain attack in which hackers stole more than 3,325 secrets.
You can read more details here: https://blog.gitguardian.com/ghostaction-campaign-3-325-secrets-stolen/
Jim Routh, Chief Trust Officer at AI-based identity security and governance solutions provider Saviynt, commented:
“This incident provides cyber professionals with an excellent example of how malicious threat actors can operate at scale by using compromised credentials for accounts that are part of the software supply chain. It is an extended attack surface for cyber criminals given the fundamental changes to software assembly using essential cloud accounts.
“These types of incidents will (unfortunately) continue until enterprises figure out that identity security is essential when establishing and managing all accounts. That means that your IAM practices must be applied when setting up, configuring cloud and managing (SaaS) accounts and not leaving it for your software engineers to figure out. The large scale use of tokens by cloud providers offers convenience in authentication which is positive, but extends the attack surface when credentials are easily compromised.
“Identity security today (and tomorrow) means the application of identity management for the full lifecycle across all types of human and non-human accounts. This starts with ways to identify existing accounts, create a data lake for them and their uses, and uniformly apply identity access management across all enterprise accounts. The majority of enterprises today apply identity security capabilities for accounts provisioned by the operations team but not the engineering teams who need cloud access to assemble software. Until this changes, we will see more cases of compromised credentials used by threat actors impacting the software supply chain.
“Cloud accounts set up for software engineers represent privileged accounts where privileges need more real time protections. This is the next generation of privileged access management (PAM) to reduce the use of compromised credentials.”
Supply chain attacks are all the rage right now. Organizations need to take action to ensure that they are not victims of a supply chain attack by doing everything possible to minimize their risk. And I do mean everything possible.
Share this:
Like this:
Related
This entry was posted on September 9, 2025 at 10:37 am and is filed under Commentary with tags Hacked. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.