Cloud Native Computing Foundation is a organization tracked across 2 threat clusters and 2 intelligence report mentions on ThreatCluster. First observed March 3, 2026; most recent activity May 11, 2026.
A targeted campaign exploiting GitHub Actions' pull_request_target trigger was identified, allowing attackers to execute malicious code with elevated privileges. This vulnerability has been documented since 2021 but…
An AI-powered bot, known as hackerbot-claw, executed a week-long attack on CI/CD pipelines of major open-source GitHub repositories, leading to remote code execution vulnerabilities. The attack compromised at least five…