GitHub Workflow Bug Lets Attackers Run Code on Microsoft Repositories
A flaw in a GitHub Actions workflow in Microsoft’s Windows-driver-samples repo allowed attackers to inject Python code and execute it remotely, risking exposure of sensitive CI/CD secrets.
Source: Tenable
Read more: CyberSecBrief

















