read.cash Log in
@typecurry more from that month

駭客濫用GitHub Actions功能以於GitHub伺服器上挖礦 https://www.ithome.com.tw/news/143634 「在駭客提出Pull Request請求之後,GitHub系統就會建立一個虛擬機器以讀取惡意分支的程式碼,接著就會在GitHub的架構上下載挖礦程式,利用GitHub伺服器來替駭客挖礦」 「駭客的攻擊鎖定了採用GitHub Actions的儲存庫,相關攻擊於去年11月便已現身。Perdok透露,至少有一個帳號提交了數百個含有惡意程式碼的Pull Requests,且單次攻擊就能遞送100個挖礦程式」 居然還有這招 XD #PttDigiCurrency

1 comment

Log in to join in Reading is open to everyone. Replying needs an account.