Security Boulevard
Read post

Long Live the Pwn Request: Hacking Microsoft GitHub Repositories and More

Pwn Requests and Injection attacks are an attack type that exploits a vulnerability where a repository runs a workflow on a pull_request_target trigger and proceeds to check out and run code from the PR branch. The CISA has even released a cybersecurity information sheet (CSI) on how organizations can secure their CI/CD pipelines.

    #security#microsoft#github#azure#vulnerability#github-actions#supply-chain#offensive-security
Sep 26, 2023•14m read time•From securityboulevard.com
Post cover image
Table of contents
Pwn Requests & Workflow Event Code InjectionFinding Vulnerable Repositoriesmicrosoft/confidential-sidecar-containersmicrosoft/gpt-reviewredhat-performance/quads (and more!)Pwn Requests: A Problem that Just Won’t Go AwayReferences
12 Impressions
Security Boulevard's image
Security Boulevard

Security Boulevard is a leading cybersecurity news and information portal, offering articles, analys...

2.5K Followers

•

2.2K Upvotes

Would you recommend this post?

Copy link
WhatsApp
Facebook
X
New Squad
  • © 2026 Daily Dev Ltd.
  • Guidelines
  • Explore
  • Tags
  • Sources
  • Squads
  • Leaderboard