GitHub Action tj-actions/changed-files was compromised in supply chain attackSecurity Affairs·Mar 18, 10:17 UTC · Mar 18, 2025VulnerabilityCVE-2025-30066147
Miasma Worm Hits 73 Microsoft GitHub Repositories in Major Supply Chain AttackThe Hacker News·Jun 9, 05:50 UTC · Jun 9, 2026Vulnerability142
Miasma Supply Chain Attack Compromises Red Hat npm Packages with CredentialThe Hacker News·Jun 2, 08:55 UTC · Jun 2, 2026Vulnerability42
GitHub restores code following malicious changes to tjThe Record·Mar 17, 20:37 UTC · Mar 17, 2025VulnerabilityCVE-2025-3006635
ThreatsDay Bulletin: SMS Blaster Busts, OpenEMR Flaws, 600K Roblox Hacks and 25 More StoriesThe Hacker News·May 1, 07:21 UTC · May 1, 2026VulnerabilityCVE-2019-0708147
GitHub Action Compromise Puts CI/CD Secrets at Risk in Over 23,000 RepositoriesThe Hacker News·Mar 18, 04:03 UTC · Mar 18, 2025VulnerabilityCVE-2025-30066CVE-2023-49291160
tj-actions Supply Chain Attack Exposes 23,000 OrganizationsInfosecurity Magazine·Mar 17, 10:00 UTC · Mar 17, 2025VulnerabilityCVE-2025-3006647
Securing GitHub Actions for a safer DevOps pipelineHelp Net Security·Oct 2, 00:00 UTC · Oct 2, 2023Vulnerability42