Skip to content

Cordyceps Supply chain Vulnerability Impacting Code Repositories at thousands of Organizations

Gbhackers Mayura Kathir June 23, 2026

A pervasive CI/CD vulnerability pattern dubbed “Cordyceps” reveals a supply chain vulnerability that lets unauthenticated attackers seize control of Git-based workflows and, by extension, the software artifacts they produce. The issue is not a single bug in GitHub or any one tool; it is a systemic class of insecure workflow compositions. Command injection, broken authentication […]

Extracted Entities