Hackers Abuse GitHub Actions to Steal SSH Keys, Cloud Credentials and Access Tokens
Hackers are abusing GitHub Actions to steal SSH keys, cloud credentials, and access tokens through malicious workflows disguised as security checks. The workflows targeted 2,577 secrets, but targeting did not always translate into theft. Researchers …