GitHub Action is a tool tracked across 3 threat clusters and 3 intelligence report mentions on ThreatCluster. First observed April 24, 2026; most recent activity May 19, 2026.
A malicious version of the Bitwarden CLI password manager was distributed via npm, affecting version 2026.4.0 for a brief window on April 22, 2026. The attack exploited a compromised GitHub Action in Bitwarden's CI/CD…
Google has issued urgent security updates for its Gemini CLI and GitHub Action to address a critical vulnerability, identified as GHSA-wpqr-6v78-jr5g. This flaw allows for Remote Code Execution (RCE) attacks due to…
A supply chain attack has compromised the GitHub Action 'actions-cool/issues-helper', exposing sensitive CI/CD secrets. The attacker manipulated Git tags, redirecting them to an imposter commit (1c9e803) without…