Cordyceps CI/CD Flaws & Cisco Zero-Days

Cordyceps CI/CD Flaws & Cisco Zero-Days: June Brief

📋 Key Takeaways
  • Security researchers at Novee Security disclosed an exploitable pattern in CI/CD workflows codenamed Cordyceps: any unauthenticated GitHub user can hijack workflows, forge approvals, push malicious code, and steal credentials — no organizational membership, no special privileges.
  • Mandiant revealed that an unknown threat actor exploited CVE-2026-20245 (CVSS 7.8) as a zero-day at least two months before public disclosure.
  • A coordinated law enforcement operation disrupted the infrastructure behind Amadey and StealC malware campaigns
  • The month’s most significant trend: security researchers describe AI entities that don’t merely suggest attack code but actively test, iterate, and weaponize exploits at machine speed — the “apex agentic adversary.”
9 min read · 1,691 words
Educational & Ethical Use Only — This article is provided for educational and ethical cybersecurity research purposes only. The techniques described should only be used on systems you own or have explicit permission to test. Always follow responsible disclosure and the laws applicable to you. Mitigations are included so engineers can harden real systems.
Security· 9 min read

A fungus that hijacks its host’s body to spread. That’s the name security researchers gave the CI/CD flaw class where an unauthenticated stranger seeds your pipeline and lets your own automation do the infecting. June 2026’s brief: Cordyceps, a Cisco zero-day with anti-forensics, a 27-million-credential takedown, and adversaries that weaponize at machine speed.

Quick Answer

Four stories define June 2026: the “Cordyceps” CI/CD pattern (Novee Security) lets any free GitHub account hijack workflows, forge approvals, and steal secrets — 300+ of ~30,000 scanned high-impact repos were fully exploitable, including at Microsoft, Google, Apache, and Cloudflare; Cisco’s SD-WAN Manager CVE-2026-20245 (CVSS 7.8) was exploited as a zero-day for at least two months pre-disclosure with anti-forensic tradecraft; an international operation dismantled Amadey/StealC infrastructure (326 servers, 142 domains, 27M credentials, $47M in crypto); and “agentic adversaries” — AI that tests and weaponizes exploits autonomously — are compressing discovery-to-weaponization from weeks to hours. Defender priorities: audit GitHub Actions for Cordyceps patterns now, patch CVE-2026-20245 now, cut LLM/agent infrastructure access to least privilege, and track CISA KEV weekly.

The Cordyceps CI/CD Vulnerability

Security researchers at Novee Security disclosed an exploitable pattern in CI/CD workflows codenamed Cordyceps: any unauthenticated GitHub user can hijack workflows, forge approvals, push malicious code, and steal credentials — no organizational membership, no special privileges. A free account is the entire prerequisite.

Scans of roughly 30,000 high-impact repositories found more than 300 fully exploitable, including repositories at Microsoft, Google, Apache, and Cloudflare. This isn’t a plugin bug or a misconfiguration — it’s a structural weakness in how pipelines handle workflow approvals and code signing, the same class of build-system risk that has defined 2026’s supply-chain attacks.

What Makes Cordyceps Dangerous

  • No authentication required — a free GitHub account is enough
  • Full repository compromise — attacker-controlled code execution inside the pipeline
  • Credential theft — secrets and tokens exposed through workflow manipulation
  • Supply-chain cascade — compromised repos propagate to downstream consumers, the same amplification that made the AUR package hijacks and node-ipc incident land so hard

Cisco SD-WAN Zero-Day: CVE-2026-20245

Mandiant revealed that an unknown threat actor exploited CVE-2026-20245 (CVSS 7.8) as a zero-day at least two months before public disclosure. The Cisco Catalyst SD-WAN Manager flaw allows an authenticated local attacker to execute arbitrary commands with elevated privileges — effectively root on the network’s control plane.

The standout detail is the anti-forensic tradecraft: the actor selectively deleted and restored system configuration files to avoid detection while maintaining persistence. We covered this exploitation wave in the June zero-day report — patching is a same-day item, not a queue item.

Amadey and StealC Takedown

A coordinated law enforcement operation disrupted the infrastructure behind Amadey and StealC malware campaigns:

  • 326 servers and 142 domains dismantled
  • 27 million stolen credentials recovered
  • $47 million in cryptocurrency identified and restricted
  • Joint operation spanning the Netherlands, Canada, Germany, and the US

It follows a separate cleanup of nearly 15,000 infected WordPress sites tied to SocGholish — a scale reminder that CMS estates remain prime loader territory. If you run WordPress, the endpoint-side pressure and this takedown are the same story: initial-access markets at industrial scale.

The Rise of the “Apex Agentic Adversary”

The month’s most significant trend: security researchers describe AI entities that don’t merely suggest attack code but actively test, iterate, and weaponize exploits at machine speed — the “apex agentic adversary.”

  • Discovery-to-weaponization compression: what took weeks now takes hours
  • Autonomous testing: agents that probe, adapt, and escalate independently — the offensive mirror of autonomous attack operations
  • Anti-forensic sophistication: AI-driven evasion adapting to defensive tooling in real time
  • Infrastructure access: organizations that granted LLMs deep infrastructure access are now the most exposed — the exact risk in AutoJack and the broader agentic attack surface

CISA KEV Catalog Updates

CISA continued adding actively exploited vulnerabilities through June — including the Android, Palo Alto, and Oracle items we tracked in the June KEV breakdown, plus the Ivanti CVE-2026-10520 addition. KEV due dates now run in days, which makes weekly cross-referencing a floor, not a ceiling. The full exploitation picture lives in our week-three intelligence brief.

Key Takeaways for Defenders

  1. Audit CI/CD pipelines immediately — check GitHub Actions workflows for Cordyceps patterns (unauthenticated trigger paths, forgeable approvals)
  2. Patch network infrastructure — CVE-2026-20245 is actively exploited with anti-forensic tradecraft; there is no deferral tier
  3. Cut AI/LLM infrastructure access to least privilege — agentic adversaries weaponize the same deep access you granted your own agents; treat agent identity like human identity
  4. Cross-reference CISA KEV weekly — due dates are days, not weeks
  5. Check WordPress installations — nearly 15,000 SocGholish-infected sites were cleaned in one operation; make sure yours isn’t in the next batch

June 2026 at a Glance

Event Class Scale Defender action
Cordyceps CI/CD pattern Supply chain 300+ repos exploitable Audit Actions workflows
Cisco SD-WAN CVE-2026-20245 Zero-day exploitation ≥2 months pre-disclosure Patch now
Amadey/StealC takedown Law enforcement 326 servers · 27M creds Rotate exposed credentials
SocGholish cleanup Malware load ~15,000 WordPress sites CMS hygiene + monitoring
Agentic adversaries AI threat evolution Weeks→hours weaponization Least-privilege agent access

Frequently Asked Questions

What is the Cordyceps CI/CD vulnerability?

An exploitable pattern in GitHub Actions workflows, disclosed by Novee Security, that lets unauthenticated users hijack workflows, forge approvals, and push malicious code. Over 300 high-impact repositories — including at Microsoft, Google, Apache, and Cloudflare — were found fully exploitable.

Is CVE-2026-20245 being actively exploited?

Yes. Mandiant confirmed an unknown threat actor exploited the Cisco Catalyst SD-WAN Manager flaw as a zero-day for at least two months before public disclosure, using anti-forensic techniques to stay hidden.

What is an agentic adversary?

An AI-powered threat actor that autonomously discovers, tests, and weaponizes vulnerabilities at machine speed — compressing the attack lifecycle from weeks to hours. The defensive answer is shrinking their blast radius: least-privilege, monitored agent access.

How many WordPress sites were affected by SocGholish?

Nearly 15,000 infected sites were cleaned in the June 2026 coordinated operation — consistent with the 14,971-site SocGholish distribution network documented in prior reporting.

{“@context”:”https://schema.org”,”@type”:”FAQPage”,”mainEntity”:[{“@type”:”Question”,”name”:”What is the Cordyceps CI/CD vulnerability?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”An exploitable pattern in GitHub Actions workflows disclosed by Novee Security that lets unauthenticated users hijack workflows, forge approvals, and push malicious code. Over 300 high-impact repositories were found fully exploitable.”}},{“@type”:”Question”,”name”:”Is CVE-2026-20245 being actively exploited?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Yes. Mandiant confirmed an unknown actor exploited the Cisco Catalyst SD-WAN Manager flaw as a zero-day for at least two months before disclosure, using anti-forensic tradecraft.”}},{“@type”:”Question”,”name”:”What is an agentic adversary?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”An AI-powered threat actor that autonomously discovers, tests, and weaponizes vulnerabilities at machine speed, compressing the attack lifecycle from weeks to hours.”}},{“@type”:”Question”,”name”:”How many WordPress sites were affected by SocGholish?”,”acceptedAnswer”:{“@type”:”Answer”,”text”:”Nearly 15,000 infected WordPress sites were cleaned in the June 2026 coordinated law enforcement operation.”}}]}

References

The CI/CD hardening stack, itemized

The CI/CD vulnerability class in this cycle joins the build-infrastructure lineage this series documents at length (TeamCity, Codecov, 3CX), and the hardening stack is now itemizable: zero-trust pipelines — every job authenticated, every credential short-lived and workload-bound rather than static secrets in environment variables; ephemeral build environments that exist for one job and disappear, eliminating the persistent-agent compromise surface; provenance from commit to artifact — signed attestations at each stage so consumers can verify the full chain, the SLSA-lineage discipline converting the sector hardest supply-chain lessons into checkable facts.

The detection layer complements hardening: pipeline-definition change monitoring (an attacker modifying build steps is the 3CX signature), egress anomalies from build runners (exfiltration staging), and artifact-integrity drift (published outputs that do not match reproducible builds). Each maps to a specific observed intrusion technique; together they cover the class.

The Cisco zero-days in the same cycle belong to the settled edge-appliance doctrine — feature inventory, patch clocks, hunt-by-default — and the pairing is instructive: the same week taught the oldest lesson (edge appliances) and the newest (CI/CD), with identical structure underneath. Trust concentrated in one system becomes attacker leverage; the defense is always inventory, isolation, verification, and monitoring, regardless of which system holds the trust this month.

Pipeline compromise response, rehearsed

The response playbook for CI/CD compromise deserves the same rehearsal investment as the prevention stack. The sequence when a pipeline incident fires: freeze artifact publication first (stop shipping potentially tainted builds — the highest-priority containment, ahead of investigation, because 3CX-class incidents spread through shipped artifacts); preserve pipeline state for forensics (job logs, runner images, definition history — the evidence that reconstructs the intrusion); rotate every credential the pipeline held (the TeamCity rotation doctrine — registry tokens, deployment keys, signing identities, cloud roles); and only then remediate and resume, with provenance verification on anything published during the exposure window.

The ordering discipline matters because the natural incident-response instinct — investigate first — burns the containment window while artifacts continue shipping. The freeze authority belongs pre-delegated: a named role that can halt publication without convening anyone, because pipeline compromise minutes are artifact-shipping minutes. Organizations that rehearsed the ordering recovered in days; the improvisers spent their first day deciding who was allowed to stop the build.

One more preparedness artifact completes the pipeline-response kit: a golden-path rebuild definition — the documented, version-controlled process for standing up a clean pipeline from scratch, with secrets re-provisioned from a vault rather than restored from the compromised estate. The organizations that recovered from build-intrusion incidents fastest all shared this artifact, because the rebuild decision arrives early in the incident (often before scope is fully known), and having the path pre-built converts the scariest decision in software security — rebuilding the factory — into a runbook step. The artifact costs a day to draft and one rehearsal per year to keep honest; its absence has cost organizations weeks during exactly the incident when weeks were unaffordable.

The rebuild path pre-built, the freeze authority pre-delegated, the rotation map pre-drawn — three artifacts, one rehearsal each per year, and the pipeline-response kit that turns the scariest software-security decision into a runbook step.

Hmmnm
Published by Hmmnm

Hands-on cybersecurity tutorials, CVE breakdowns, and guided learning paths — written and lab-tested by the Hmmnm team.

🛡️ Hmmnm also delivers this expertise as a service — security testing, assessment & training.
Keep going — the structured way
This post is one step. The learning paths chain the next ones for you, with progress tracking and no account needed.
Follow a learning path →

Prabhu Kalyan Samal

Application Security Consultant at TCS. Certifications: CompTIA SecurityX, Burp Suite Certified Practitioner, Azure Security Engineer, Azure AI Engineer, Certified Red Team Operator, eWPTX v3, LPT, CompTIA PenTest+, Professional Cloud Security Engineer, SC-900, SC-200, PSPO I, CEH, Oracle Java SE 8, ISP, Six Sigma Green Belt, DELF, AutoCAD. Writing about ethical hacking, security tutorials, and tech education at Hmmnm.