Microsoft and Google fix “Cordyceps” CI/CD flaws found across major open-source repositories
Security firm Novee identified “Cordyceps,” a class of exploitable CI/CD weaknesses in open-source repositories that could let attackers steal credentials, inject malicious code, and disrupt operations at major software organizations. The issues were found in repositories tied to Microsoft, Google, Apache, Cloudflare, and the Python Software Foundation, according to Novee. The companies said the vulnerabilities have been fixed.