#codebuild

[ follow ]
#aws
fromTechzine Global
13 hours ago
Information security

CodeBreach enables takeover of AWS GitHub repositories

An unanchored AWS CodeBuild ACTOR_ID webhook regex allowed ID eclipsing via longer GitHub numeric IDs, enabling repository takeover and credential theft.
fromTheregister
13 hours ago
Information security

A simple CodeBuild flaw put every AWS environment at risk

A CodeBuild misconfiguration allowed full takeover of AWS GitHub repositories and risked global supply-chain compromise and administrative code execution across AWS environments.
[ Load more ]