GitHub Actions Are a Huge, Overlooked Supply Chain Risk
Security researchers from Wiz detailed how attackers are compromising open-source projects via GitHub Actions to steal secrets. Major incidents like the Coinbase-linked attack show the widespread impact of these vulnerabilities.