Allgemein

AI-Powered Bot Compromises GitHub Actions Workflows Across Microsoft, DataDog, and CNCF Projects

AI-Powered Bot Compromises GitHub Actions Workflows Across Microsoft, DataDog, and CNCF Projects

AI-powered bot hackerbot-claw exploited GitHub Actions workflows across Microsoft, DataDog, and CNCF projects over 7 days using 5 attack techniques. Bot achieved RCE in 5 of 7 targets, stole GitHub token from awesome-go (140k stars), and fully compromised Aqua Security’s Trivy. Campaign included first documented AI-on-AI attack where bot attempted prompt injection against Claude Code.

By Steef-Jan Wiggers

KI-Assistent
Kontext geladen: AI-Powered Bot Compromises GitHub Actions Workflows Across M