Follow the latest coverage, related explainers and connected technology stories.
Two previously compromised GitHub Actions were reactivated and continued for more than a week to point to a malicious payload capable of execution within workflows. Researchers recommend removing the actions or pinning them to a trusted version, reviewing runs, and rotating secrets.