Jan. 17, 2024, 12:35 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news


A novel attack method on GitHub illustrates yet again why application security (AppSec) teams should be implementing in-depth security measures — beyond what legacy application security testing tools can provide.


The attack, discovered by Praetorian security researcher Adrian Khan, involves GitHub-hosted runners, which are virtual machines that execute jobs in a GitHub Actions workflow. There are two kinds of runners in GitHub Actions, which is one of the biggest continuous integration/continuous delivery (CI/CD) services in the market, largely …

actions analysis application application security application security testing application security testing tools appsec attack beyond binary binary analysis can case github github actions hack jobs legacy legacy application machines novel praetorian researcher runners security security measures security researcher security testing teams testing testing tools tools virtual virtual machines

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Risk and compliance specialist

@ ZainCash | Baghdad, Baghdad Governorate, Iraq

Information Security Compliance Analyst

@ Evelyn Partners | Liverpool, United Kingdom

Director of Security Engineering

@ Kasada | Melbourne