Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code.
GitHub Actions re-enabled with Mini Shai-Hulud payload still active
About this summary. This is a short, independently written summary of an article first published by BleepingComputer. Cyber Security News did not report or verify the underlying story. Read the original: https://www.bleepingcomputer.com/news/security/github-actions-re-enabled-with-mini-shai-hulud-payload-still-active/

Source attribution: headline and facts are from BleepingComputer (bleepingcomputer.com). Summary method: excerpt of the source description. See our source attribution policy.





