WhisperX tag archive

#secrets exfiltration

This page collects WhisperX intelligence signals tagged #secrets exfiltration. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-05-08 07:36:56 · GitHub Security Blog RSS

1. GitHub Actions Workflows Exploited in Supply Chain Attacks Targeting Secrets Exfiltration

A new attack pattern targeting the open source supply chain has emerged over the past year, with attackers systematically exploiting GitHub Actions workflows to exfiltrate secrets such as API keys. These compromises serve a dual purpose: enabling attackers to publish malicious packages from controlled infrastructure wh...