Risky Business #837 -- GitHub Actions footgun claims TanStack
TanStack compromise demonstrates how GitHub Actions misconfigurations create supply chain vulnerabilities affecting popular JavaScript frameworks used across European enterprises.
Summary written by editorial AI · Source link below
On this week’s show Patrick Gray, Adam Boileau and James Wilson discuss the week’s cybersecurity news.
They cover:
Mini Shai-Hulud and the TanStack compromise using Github Actions Instructure pays Canvas elearning platform data extortionists More Linux privilege escalation 0days! CISA helping critical infrastructure operators rearchitect their networks so they work offline
This week’s episode is sponsored by email security platform Sublime Security. Bobby Filar chats with Patrick ab
External link — opens at Risky Business in a new tab.
More from the DevSecOps Desk
- CHRONO-RESOLUTION: A Dependency Resolution Dataset at Release Points for npm, PyPI, and crates.io Packages20 Jul
- SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts19 Jul
- Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT17 Jul
- VulnHunter: Capital One's agentic AI code security tool17 Jul
- The Prover Is the Judge: Verified Security Software from AI Coding Agents in Ada/SPARK17 Jul