Cybersecurity researchers have disclosed details of an ongoing credentialtheft campaign that has compromised two highprofile opensource maintainer accounts to push a malicious workflow into over 340 repositories. "Using the account of Takashi Kitao, author of the 18,400star game engine pyxel, the attacker pushed a malicious workflow to 27 repositories starting at 1320 UTC," StepSecurity.📖 Read more.
🔗 Via "The Hacker News"
----------
👁️ Seen on @cibsecurity