Risky Business

Risky Business #784 -- GitHub supply chain attack steals secrets from 23k projects

20 snips
Mar 19, 2025
Aaron Steinke, Head of Infrastructure at La Trobe Financial, shares his insights on implementing Zero Networks' micro-segmentation product, transforming a legacy tech environment. The conversation dives into a significant GitHub supply chain attack that compromised 23,000 projects, revealing sensitive information. They also discuss the complex geopolitical tensions surrounding cyber threats, especially between Taiwan and China, and the rise of malicious hacks involving North Korean groups. Steinke's experience illustrates the challenges and innovations in modernizing cybersecurity practices.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

GitHub Supply Chain Attack

  • A GitHub Action called "changed-files" was backdoored to steal credentials from 23,000 projects.
  • The backdoor exfiltrated secrets by writing them to public build logs.
INSIGHT

China Doxes Taiwanese Military Hackers

  • The Chinese government publicly attributed cyberattacks to Taiwanese military personnel.
  • This doxing is unusually threatening due to potential future conflicts.
ADVICE

LNK File Abuse

  • Windows LNK files can hide malicious commands using whitespace, which is a known APT tactic.
  • Microsoft argues this isn't a vulnerability, but its widespread APT use suggests otherwise.
Get the Snipd Podcast app to discover more snips from this episode
Get the app