AI Risk Clock
Doomsday Clock5 min to midnight
⚖️ Neutral edit
Dark Reading2026-06-23

'Cordyceps': Malicious Pull Requests Threaten CI/CD Workflows

SafetyResearch

A new class of CI/CD workflow vulnerability named 'Cordyceps' has been discovered. The weakness allows attackers to use malicious pull requests to compromise systems. It affects tools including Google's AI Agent Development Kit and Microsoft's Azure Sentinel.

The vulnerability exploits the trust inherent in pull request workflows, enabling unauthorized code execution or data exfiltration. Security researchers detailed the attack vector, emphasizing that it targets the CI/CD pipeline itself rather than the application code. Both Google and Microsoft have been notified of the issue.

This discovery highlights ongoing security challenges in software development pipelines, particularly as AI tools integrate more deeply into developer workflows. The 'Cordyceps' name refers to the parasitic fungus that takes over its host, reflecting the nature of the attack.

Read this story in another voice
● REC · 2026