What happened
Novee Security has identified a critical class of CI/CD vulnerability, dubbed Cordyceps, that exposes more than 300 GitHub repositories to full attacker takeover. The flaw exploits weaknesses in workflow configurations, potentially allowing malicious actors to hijack pipelines at organizations including Microsoft, Google, and Apache. Separately, two members of the notorious Scattered Spider cybercrime group entered guilty pleas on the opening day of a UK trial, admitting to charges tied to an August 2024 attack that severely disrupted Transport for London's public transit operations.
Why it matters for your business
The Cordyceps pattern represents a systemic risk to any organization that consumes open-source packages built through compromised pipelines — a category that encompasses virtually every modern software team. A poisoned dependency from a trusted source like Apache or Google can propagate malware deep into production environments before detection. The Scattered Spider guilty pleas serve as a separate but parallel warning: ransomware and social-engineering crews are actively targeting critical infrastructure and large enterprises, and prosecution timelines can stretch more than a year after an incident. Security teams should audit CI/CD workflow permissions immediately and review their software bill of materials for exposure to affected upstream repositories.
What to watch next
Novee Security is expected to release a fuller technical disclosure of the Cordyceps exploit chain, which will likely prompt rapid patching activity across affected repositories and renewed scrutiny of GitHub Actions permission models. In the Scattered Spider case, sentencing has yet to be determined, and additional group members may face charges, signaling continued law enforcement focus on cybercrime networks operating across jurisdictions.
