Many businesses use GitHub Action Secrets to store and protect sensitive information, such as credentials, API keys, and tokens used in CI/CD workflows. These private repositories are widely considered secure and locked down. However, attackers are now exploiting this blind trust, according to new research from Wiz ’s Customer Incident Response Team .
See also: Russian Ransomware Groups Abuse AdaptixC2 for Attacks

They found that malicious actors are using exposed GitHub Personal Access Tokens (PATs) to gain access to GitHub Action Secrets and break into cloud environments, causing chaos.
“The main problem is the presence of these secrets in the repositories,” said David Shipley of Beauceron Security. GitHub Action Secrets are no longer secrets. Wiz estimates that 73% of organizations using private GitHub Action Secrets repositories store cloud service provider (CSP) credentials in them.
When PATs, which allow developers and automated bots to interact with GitHub repositories and workflows, are exploited, attackers can easily move laterally into control planes . PATs can become a “powerful springboard” that allows attackers to impersonate developers and perform a range of activities, explained Erik Avakian, technical advisor at Info-Tech Research Group.
With this access, malicious actors can “explore” various repositories and workflows and look for anything that suggests cloud access, configuration data, scripts and hidden secrets, he noted. If they gain access to real cloud credentials, “they have the keys to the company’s AWS bucket, Azure subscriptions and other workflows.”
See also: Hackers target sites through outdated WordPress plugins

They can then launch cloud resources, gain access to databases, steal source code, install malicious files like crypto miners, introduce malicious workflows, or even migrate to other cloud services, while creating persistence mechanisms so they can return whenever they want.
Cloud infrastructure and cloud development environments must be properly locked down, essentially “zero-trust” through micro-segregation and privileged user management to contain them and prevent lateral movement.
Most importantly, move cloud secrets outside of GitHub workflows and ensure that there is an appropriate amount of monitoring and log review processes in place to flag surprises or unexpected workflow or cloud build events.
Beauceron’s Shipley agreed, saying that businesses need a multi-pronged strategy, good monitoring, immediate response plans, and developer training processes reinforced with “meaningful consequences” for noncompliance. Developers need to be incentivized to follow secure coding best practices. Creating a strong security culture within development teams is of paramount importance.
See also: Banking trojan Astaroth abuses GitHub

General increases in security awareness make it harder for criminals to gain access and identities and compromise systems. “In some ways, that’s a good sign,” Shipley said.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
