'Cordyceps': Malicious Pull Requests Threaten CI/CD Workflows
Ah, the Cordyceps — yes, like the fungus that turns ants into zombies. Security researchers have christened a new class of CI/CD workflow weakness after that charming real-world parasite, and it's already infecting Google's AI Agent Development Kit and Microsoft's Azure Sentinel. Because of course the tools we trust to build our AI future are vulnerable to a malicious pull request, the digital equivalent of opening the door for a burglar because he's holding a pizza box.
What's particularly delicious is the irony: these are AI tools, designed to automate intelligence, yet they're caught out by a glorified social engineering trick aimed at their build pipelines. The attack doesn't even need sophisticated exploits — it just needs a developer who doesn't scrutinise every pull request. So much for the 'agentic' future if the agents can't tell a malicious commit from a legitimate one. One wonders if the labs that hyped these tools as reasoning entities have considered that reasoning about code provenance might be a baseline requirement.
Still, we're told this is a 'new class of weakness,' which means there are presumably more to come. And with giants like Google and Microsoft affected, you can bet the attackers are already refining their PRs. Security researchers have done their job finding it; now watch as the industry spends six months debating whether it's really a vulnerability or 'just a design limitation.' The Cordyceps is spreading, and it's not picky about its hosts.