Autonome "Hackerbot-Klaue" nutzt GitHub Actions aus
Autor: Ddos
⚠️ CVE-Referenzen:
CVE-2025-54416
CVE-2025-54594
Zusammenfassung
Eine neue autonome Kampagne, die als "Hackerbot-Klaue" bezeichnet wird, missbraucht GitHub Actions, um sich in Repositorys einzuschleusen. Dies kann zu Übernahmen von AWS-Konsolen führen. Die Schwachstelle CVE-2025-54594 in React Native Bottom Tabs' GitHub Actions wurde ebenfalls entdeckt und ermöglicht Remote-Code-Ausführung. Sicherheitsverantwortliche sollten umgehend Gegenmaßnahmen ergreifen und ihre GitHub-Aktionen überprüfen.
The post Security Alert: “Hackerbot-Claw” Autonomous Campaign Exploits GitHub Actions appeared first on Daily CyberSecurity.
Related posts:
CodeBreach: Missing Regex Anchors Exposed AWS Console to Takeover
Critical Command Injection (CVE-2025-54416) in tj-actions/branch-names GitHub Action Exposes 5,000+ Repos
Critical RCE Flaw (CVE-2025-54594) in React Native Bottom Tabs’ GitHub Actions Exposed Secrets
Quelle: securityonline.info