Critical AWS supply chain vulnerability could have allowed hackers to take over key GitHub repositories


  • Wiz discovered a misconfiguration of AWS CodeBuild allowing unauthorized privileged builds, dubbed “CodeBreach.”
  • Flaw Risked Exposing GitHub Tokens and Enabling Supply Chain Attacks in AWS Projects
  • AWS resolved the issue within 48 hours; no abuse detected, users are advised to secure CI/CD configurations

A critical misconfiguration in Amazon Web Services’ (AWS) CodeBuild service has exposed several AWS-managed GitHub repositories to potential supply chain attacks, experts have warned.

Security researchers Wiz discovered the flaw and reported it to AWS, helping to remedy the issue.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top