الرئيس التنفيذي
أشرف الحادي

رئيس التحرير
فاطمة مهران

Kaspersky Uncovers Over 250,000 Potential Security Issues in GitHub Actions Workflows

Kaspersky’s Global Research and Analysis Team (GReAT) has conducted a major review of the GitHub Actions workflows within top-starred repositories. Leveraging newly introduced Kaspersky Container Security capability, the researchers have discovered 8 repositories with critical misconfigurations that could lead to supply chain compromise.

Open-source components are now indispensable to modern software engineering. However, they also introduce hidden vectors for supply-chain attacks, such as the prominent Mini Shai-Hulud campaign conducted by TeamPCP in May 2026. This attack exploited weaknesses in GitHub Actions build pipelines and led to the compromise of more than 170 npm and PyPI packages, affecting projects such as TanStack, Mistral AI, and OpenSearch. In general, misconfigured GitHub Actions workflows can transform trusted development pipelines into dangerous entry points, allowing attackers to compromise automated workflows, introduce malicious code into production environments, or access critical infrastructure keys.

Kaspersky GReAT experts have completed the assessment of GitHub Actions workflows, analyzing more than 130,000 pipelines across 30,000 of the platform’s top starred repositories. Utilizing the specialized scanning ruleset introduced in the latest Kaspersky Container Security update, the researchers identified over 250,000 potential misconfigurations in continuous‑integration/continuous‑delivery (CI/CD) processes, underscoring the widespread adoption of insecure configuration practices. Only 10% of the analyzed repositories triggered no alerts at all.

Among the discovered issues 59.8 % are classified as low‑risk, 39.8 % as medium‑risk, and 0.4 % fall into the high‑risk category according to Kaspersky taxonomy. The most frequent issues involve implicitly granted or overly broad access permissions, missing version pinning for dependencies and workflow‑level settings. Fewer repositories expose top-level secrets, use unsafe run conditions, or process external data insecurely, potentially leading to more severe compromises.

Among 200 repositories identified as high-risk, the team discovered 8 repositories with critical flaws that could lead to supply chain compromise. The affected repositories spanned a wide range of use cases, including AI integration in enterprise environments, developer and automation services and security testing tools. The identified critical issues were reported to the respective developer.

“Over the past year, we have observed serious supply-chain attacks, that could have been prevented by following secure CI/CD configuration guidelines,” said Leonid Bezvershenko, senior security researcher at Kaspersky GReAT. “While the uncovered issues do not automatically indicate exploitable vulnerabilities, they point to areas where developers should verify and strengthen configurations. By identifying these weaknesses early, organizations can build more resilient pipelines and reduce the likelihood of supply-chain compromise. The rules developed for our container security solution provide a practical framework to identify and remediate these gaps before they can be exploited.”

To detect and mitigate potential security issues caused by misconfigurations, Kaspersky Container Security users can leverage GitHub repository scanning, whether embedded directly into CI/CD pipelines or operated in standalone mode.

Related Posts:

Madinet Masr Awards EGP 1.38 Billion for Origami at Taj City

إدراج 47 جامعة مصرية في تصنيف UI GreenMetric للاستدامة لعام 2026

حجر أساس لمشروع أعلاف باستثمارات صينية.. والزراعة تؤكد دعم الشراكة مع القطاع الخاص

Zoho Launches Agent-Ready Catalyst Platform for AI App Development

Turkish Airlines Named Europe’s Best Airline for the 11th Time

NILEWOOD Expands in Saudi Arabia at Saudi Wood Show 2026

Turkish Airlines and Air China Expand Codeshare Agreement

PATRIZIA appoints Hassan Awada as Senior Executive Officer to lead and accelerate Middle East expansion

آخر الأخبار
الذكاء الاصطناعي في الفصول الدراسية.. كيف يتخيل الجيل Z مستقبل التعليم؟ ڤاليو تنجح في إتمام إصدار سندات توريق بقيمة 945.8 مليون جنيه إم إن تي-حالاࣧ تنجح فى إتمام مجموعة من إصدارات سندات التوريق بقيمة تتجاوز 4 مليار جنيه بنهاية الربع ... تنميه تتعاون مع«ايسكور»و«سينابس أناليتكس»لتطوير قرارات الائتمان بالذكاء الرقمي مع هيونداي توسان.. راحة بالك تمتد لـ3 سنوات أو 60 ألف كيلومتر مع باقة الصيانة الخاصة من جي بي أوتو قمة الابتكار الجامعي 2026 تعلن الفرق الفائزة بمشاركة 100 مشروع من 30 جامعة سالي سلامة أمام الاختبار الأصعب في نيسان مصر.. هل تعود الثقة من بوابة العميل والأمان؟ محافظ البنك المركزي يبحث مع مسؤول «التمويل الدولية» تعزيز التعاون المشترك وزير الأوقاف يلتقي المشرفات من الواعظات عبر تقنية الاتصال المرئي لمتابعة العمل الدعوي مصر تدين اقتحام المستوطنين الإسرائيليين للمسجد الأقصى المبارك بنك القاهرة وشركة فيزا يوقعان اتفاقية تعاون لدعم تطوير حلول ومنتجات دفع جديدة محافظ البنك المركزي ووزير الصناعة يطلقان صندوق إعادة هيكلة المصانع المتعثرة برأسمال مليار جنيه إف سي بايرن ميونخ يؤسس أكاديمية تعمل على مدار العام في الشرق الأوسط، ويقدّم نموذجه المتميز لتطوير ال... دولة الإمارات تجدد التزامها بالتنمية المستدامة خلال الاجتماع السنوي لمجلس محافظي البنك الآسيوي للاس... المكتب الطبي يعلن حصول «مستشفيات الشيخ خليفة» على اعتماد «مسار التميّز بامتياز» من «المركز الأمريكي ... مجموعة دلسكو تطلق برنامج «خطوة» للمواهب الوطنية لتطوير وتمكين الكفاءات الإماراتية شراكة بين "عزيزي" و"كوني" لتطوير أنظمة النقل العمودي في "برج عزيزي" أومودا وجايكو تستعد للكشف العالمي عن ‎OMODA X‎ وتقنيات هجينة وذكية جديدة في الصين مجلس الوزراء: تخصيص 150 فدانًا لـ "قصر العيني" في أكتوبر لا يعني التخلي عن موقعه التاريخي شركة «Rock Developments» تعزز ثقة عملائها وتحتفي بشركاء النجاح خلال «ROCK EXPO II»