
Cordyceps Flaw Exposes 300+ GitHub Repos at Microsoft, Google, and Apache to Supply Chain Attacks
Researchers at Novee Security found a systemic CI/CD misconfiguration that lets anyone with a free GitHub account inject malicious code into packages published by major tech firms.










