Feb. 3, 2024, 1 a.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

A GitHub Actions workflow could have been used for a command injection vulnerability in Bazel, which had the potential for threat actors to add malicious code into the production environment for projects using the Google open-source product.


Article Link: Google supply chain bug patched in code-testing tool Bazel | SC Media


1 post - 1 participant


Read full topic

actions article bug code command command injection environment github github actions google injection link malicious media product production projects supply supply chain testing testing tool threat threat actors tool vulnerability

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC