Skip to content
Threat Note Threat Note

Aggregating Cyber Insights

  • Articles
  • Breaches
  • Learning
  • News
  • Podcast
  • Research
  • Toolkit
  • Vulnerabilities
  • Webinars
  • About Us
  • Home
  • Vulnerabilities
  • From Cybersecurity Help – GitHub action compromise exposes secret tokens in build logs
From Cybersecurity Help – GitHub action compromise exposes secret tokens in build logs
Posted inVulnerabilities

From Cybersecurity Help – GitHub action compromise exposes secret tokens in build logs

Posted by shaikh Saqib March 17, 2025

The attack, which occurred sometime before March 14, 2025, involved a threat actor modifying the code of the tj-actions/changed-files GitHub Action. 

​ Read More 

​ 

Share this:

  • Click to share on Facebook (Opens in new window) Facebook
  • Click to share on X (Opens in new window) X
Tags:
AWS access key leakbreachesCI/CD pipeline securityCI/CD security incidentcompromised CI/CD pipelinescompromised GitHub bot accountCVE-2025-30066cyber awarenesscyber defensecyber protectioncyberattackscybersecuritydata leaksdigital privacyGitHub Actions security breachGitHub Gist malwareGitHub PAT security riskGitHub repository attackGitHub secrets exposureGitHub token compromisehacksinfosecleaked RSA private keysmalicious GitHub Actionnetwork securitynoteonline securitypreventing GitHub supply chain attacks.Python script dumping secretssecret exposure in build logssecurity best practices for GitHub Actionssecurity incidentssecurity perspectivesupply chain attack on GitHubthreatthreat intelligencethreat notethreatnotetj-actions/changed-files vulnerability
Last updated on March 19, 2025

Latest Posts

  • From Security Week – Juniper Networks Patches Critical Junos Space VulnerabilitiesOctober 10, 2025
  • From Security Week – ZDI Drops 13 Unpatched Ivanti Endpoint Manager VulnerabilitiesOctober 10, 2025
  • From The Hacker News – From LFI to RCE: Active Exploitation Detected in Gladinet and TrioFox VulnerabilityOctober 10, 2025
  • From Cyber Security News – New Android Malware ClayRat Mimic as WhatsApp, Google Photos to Attack UsersOctober 10, 2025
  • From Security Week – Apple Bug Bounty Update: Top Payout $2 Million, $35 Million Paid to DateOctober 10, 2025