AI Coding Agents Could Amplify Cordyceps CI/CD Supply-Chain Risks
CI/CD systems are central to automating software builds, testing and releases, while GitHub Actions workflows often hold repository write permissions, cloud credentials and deployment keys. Novee Security named a series of configuration weaknesses “Cordyceps.” AI coding agents that rapidly generate workflows without human review could replicate the same vulnerabilities at scale, magnifying the supply-chain impact.
Novee Security disclosed on June 23, 2026, that after scanning about 30,000 high-impact GitHub repositories, it flagged 654 suspicious cases and confirmed that more than 300 were fully exploitable. Affected projects were linked to Microsoft, Google, Apache, Cloudflare and the Python Software Foundation. Attackers needed only a free account to hijack workflows, push code or steal credentials.
All Coverage
1 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.