GitHub suffers a cascading supply chain attack compromising CI/CD secrets
infoworld.comWidening impact assessment The tj-actions developers had previously reported they could not determine exactly how attackers gained access to their GitHub personal access token. This new finding from Wiz provides the missing link, suggesting that the initial reviewdog compromise was … Read more