A misconfigured AWS CodeBuild webhook allowed bypass of actor ID checks, risking takeover of four AWS GitHub repositories ...
Wiz researchers investigated and found the core of the flaw, a threat actor ID bypass due to unanchored regexes, and notified ...
The vulnerability was spotted in August 2025, so users should patch now.
AWS recently published a security bulletin acknowledging a configuration issue affecting some popular AWS-managed open-source ...