Google researchers disclose high-severity vulnerability affecting GitHub

clock • 3 min read

The bug makes GitHub Action's workflow commands vulnerable to injection attacks, according to researchers

Google's Project Zero researchers have disclosed a high-severity vulnerability in GitHub, which, they say, could allow attackers to remotely execute code on affected systems. The bug was discove...

To continue reading this article...

Join Computing

  • Unlimited access to real-time news, analysis and opinion from the technology industry
  • Receive important and breaking news in our daily newsletter
  • Be the first to hear about our events and awards programmes
  • Join live member only interviews with IT leaders at the ‘IT Lounge’; your chance to ask your burning tech questions and have them answered
  • Access to the Computing Delta hub providing market intelligence and research
  • Receive our members-only newsletter with exclusive opinion pieces from senior IT Leaders

Join now


Already a Computing member?


You may also like
Microsoft passwords and keys leaked through misconfigured Azure storage

Threats and Risks

38TB of exposed data included passwords for Microsoft services, secret keys and conversations

clock 19 September 2023 • 3 min read
GitHub announces passwordless authentication trial

Security Technology

The trial can be considered a milestone in the long demise of passwords

clock 13 July 2023 • 2 min read

More on Threats and Risks

Microsoft warns of new ransomware campaign by the Twisted Spider group

Microsoft warns of new ransomware campaign by Twisted Spider group

Uses malvertising to spread Danbot Trojan, then Cactus ransomware

John Leonard
clock 01 December 2023 • 2 min read
Google rushes out patch for Chrome zero-day with exploit available in the wild

Google rushes out patch for Chrome zero-day with exploit available in the wild

Other Chromium-based browsers are also vulnerable to the flaw in the Skia graphics library

clock 30 November 2023 • 3 min read
18,000 customers at risk of phishing attacks after security firm Otka hacked

Customers at risk of phishing attacks after hack, Okta warns

Software security firm Otka has warned that some of its 18,000 corporate and government customers have been left vulnerable to phishing attacks after hackers broke into its computer systems a month ago.

clock 30 November 2023 • 1 min read