News

A new supply chain attack on GitHub, dubbed 'GhostAction,' has compromised 3,325 secrets, including PyPI, npm, DockerHub, ...
On September 5, 2025, GitGuardian discovered GhostAction, a massive supply chain attack affecting 327 GitHub users across 817 ...
This breach exposed a critical weakness in the current CI/CD security model: the assumption that automated workflows are inherently benign. The GhostAction supply chain campaign underscores how ...
Multiple high-profile open-source projects, including those from Google, Microsoft, AWS, and Red Hat, were found to leak GitHub authentication tokens through GitHub Actions artifacts in CI/CD ...
AWS has recently announced that AWS Lambda now supports GitHub Actions, providing a simplified way to deploy changes to ...
Amazon's investments in AI chips like Trainium2 and platforms like Bedrock strengthen AWS’s leadership in scalable, ...
GitHub now scans for secret leaks in developer workflows The new tool aims to protect developers against API and token exposure.
AWS announced the availability of SaaS Boost on GitHub today. The project is the latest in a series of open-source tools the cloud giant has released to simplify customers’ software projects.