GitHub Actions is at risk from typosquatting, where attackers exploit minor misspellings in action names to inject malicious code. Researchers found numerous instances where slight errors in action names could lead to running harmful code. Developers are advised to carefully verify action names, use trusted sources, and regularly check their CI/CD workflows for such vulnerabilities.
https://thehackernews.com/2024/09/github-actions-vulnerable-to.html
crack-vault.de
#crackvault