A critical vulnerability in the AWS supply chain could have allowed hackers to seize key GitHub repositories



  • Wiz discovered an AWS CodeBuild misconfiguration that allowed builds with unauthorized privileges, called “CodeBreach.”
  • The flaw risked exposing GitHub tokens and enabling supply chain attacks across all AWS projects.
  • AWS fixed the issue within 48 hours; no abuse detected, users urged to protect CI/CD configurations

A critical misconfiguration in the Amazon Web Services (AWS) CodeBuild service exposed several AWS-managed GitHub repositories to potential supply chain attacks, experts warned.

Wiz security researchers discovered the flaw and reported it to AWS, which helped fix the issue.



Leave a Comment

Your email address will not be published. Required fields are marked *