CISA Alerts Regarding Ongoing Exploitation in GitHub Action Supply Chain Breach

The U.S.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a warning on Tuesday about a security vulnerability related to the supply chain breach affecting GitHub Action, specifically the tj-actions/changed-files repository, which has been included in its Known Exploited Vulnerabilities (KEV) list.
This critical vulnerability, identified as CVE-2025-30066 (CVSS score: 8.6), concerns the unauthorized access of the GitHub Action to insert malicious code that allows for remote execution.

About Author

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.