Credential-stealing GitHub Actions workflows planted in tens of thousands of repositories
Attackers using hijacked maintainer accounts are pushing fake 'security audit' GitHub Actions workflows that harvest cloud, AI and source-control secrets, The Hacker News reported.
