Back to news

GitHub Patches CI/CD Exploit Vector; Android Botnet Tied to Israeli Proxy Firm

Two cybersecurity developments expose risks in open-source pipelines and consumer device ecosystems that directly affect enterprise security posture.

GitHub Patches CI/CD Exploit Vector; Android Botnet Tied to Israeli Proxy Firm

What happened

GitHub announced that its official actions/checkout action will be updated effective June 18, 2026, to block a class of attacks known as pwn requests — exploits that abuse the pull_request_target workflow trigger to execute arbitrary code with full repository privileges. Separately, researchers from multiple security firms this week attributed the four-year-old Popa botnet to NetNut, a residential proxy service operated by publicly-traded Israeli company Aladinme. The Popa botnet has quietly conscripted millions of Android-based consumer TV boxes, using them to route traffic tied to ad fraud, credential theft, and large-scale data scraping operations.

Why it matters for your business

For engineering and DevOps teams, the pwn request vector represents a meaningful supply chain risk: a misconfigured CI/CD workflow can hand an external contributor elevated access to secrets, production credentials, and deployment pipelines. GitHub's fix addresses the most common patterns, but teams should audit existing workflows now rather than waiting for the update to do the heavy lifting. The Popa botnet story carries a different but equally urgent warning — legitimate-looking commercial proxy services can be built on infrastructure that is itself malicious. Any organization routing traffic through residential proxy networks for competitive intelligence, ad verification, or scraping should scrutinize its vendor relationships and validate that upstream providers are not monetizing compromised consumer devices.

What to watch next

GitHub's June 18 deadline gives development teams a narrow window to review pull_request_target usage across their repositories before the change takes effect — expect tooling vendors and security platforms to release workflow scanning features in the coming weeks. On the botnet front, regulatory and legal scrutiny of NetNut and its parent company is likely to intensify, and the case may prompt broader industry examination of how residential proxy markets are licensed and audited. Both stories signal that supply chain accountability — whether in code or in network infrastructure — is moving from best practice to baseline expectation.

Sources

Want this kind of clarity applied to your own systems?

HashWhales can review your website, infrastructure, security posture, and growth bottlenecks, then send a prioritized action plan.

Free AuditChat on WhatsApp