

Risky Business #784 -- GitHub supply chain attack steals secrets from 23k projects
20 snips Mar 19, 2025
Aaron Steinke, Head of Infrastructure at La Trobe Financial, shares his insights on implementing Zero Networks' micro-segmentation product, transforming a legacy tech environment. The conversation dives into a significant GitHub supply chain attack that compromised 23,000 projects, revealing sensitive information. They also discuss the complex geopolitical tensions surrounding cyber threats, especially between Taiwan and China, and the rise of malicious hacks involving North Korean groups. Steinke's experience illustrates the challenges and innovations in modernizing cybersecurity practices.
AI Snips
Chapters
Transcript
Episode notes
GitHub Supply Chain Attack
- A GitHub Action called "changed-files" was backdoored to steal credentials from 23,000 projects.
- The backdoor exfiltrated secrets by writing them to public build logs.
China Doxes Taiwanese Military Hackers
- The Chinese government publicly attributed cyberattacks to Taiwanese military personnel.
- This doxing is unusually threatening due to potential future conflicts.
LNK File Abuse
- Windows LNK files can hide malicious commands using whitespace, which is a known APT tactic.
- Microsoft argues this isn't a vulnerability, but its widespread APT use suggests otherwise.