Critical AWS supply chain vulnerability could have let hackers take over key GitHub repositories


  • Wiz discovered misconfiguration of AWS CodeBuild that enabled unauthorized privileged builds, called “CodeBreach”.
  • Flaws risked exposing GitHub tokens and enabling supply chain attacks across AWS projects
  • AWS resolved the issue within 48 hours; no abuse detected, users are encouraged to secure CI/CD setups

A critical misconfiguration in the Amazon Web Services (AWS) CodeBuild service exposed several AWS-managed GitHub repositories to potential supply chain attacks, experts have warned.

Security researchers Wiz discovered the bug and reported it to AWS, helping to fix the problem.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top