/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Unit 42: open-source projects from Google, Microsoft, AWS, Red Hat, and others leaked GitHub auth tokens via GitHub Actions; GitHub chose not to fix the issues

Multiple high-profile open-source projects, including those from Google, Microsoft, AWS, and Red Hat, were found …

BleepingComputer Bill Toulas

Discussion

  • @yaronavital Yaron Avital on x
    7/ Major projects affected: Google's firebase-js-sdk (1.6M+ dependents!) Ubuntu's adsys Projects by Microsoft, Red Hat, AWS, OWASP, and more Full list in the blog post!
  • @yaronavital Yaron Avital on x
    3/ I discovered two types of exposed tokens: * GITHUB_TOKEN (prefix: ghs_) * ACTIONS_RUNTIME_TOKEN (a JWT) These weren't in the code, but in artifacts produced by workflows.
  • @gossy_84 Adam Goss on x
    🚨 Flaw in GitHub Action Artifacts Expose Sensitive Tokens The research highlights a security flaw in GitHub Actions artifacts, which can leak sensitive tokens, including GitHub tokens and third-party cloud service tokens. Here is what you need to know: 🧵 [image]