# Security Researchers Expose Software Supply Chain Vulnerabilities

Security researchers have identified critical vulnerabilities in software supply chain processes affecting major cloud and software providers including Microsoft, Google, Cloudflare, Apache, and Amazon. The "Cordyceps" weakness in CI/CD workflows allows malicious pull requests to access sensitive credentials and distribute harmful code, while a flaw in Amazon Q enables execution of malicious code from booby-trapped Git repositories, risking cloud credential theft. These findings underscore the urgent need for government agencies and contractors to rigorously assess vendor cybersecurity postures, enforce least-privilege principles in automated development pipelines, and incorporate enhanced security requirements in cloud service contracts.

- Procurement professionals should prioritize evaluating cloud and software vendors for mitigation of these vulnerabilities to ensure compliance with federal cybersecurity standards.
- Contracting officers may need to update solicitation requirements to include specific protections against CI/CD and repository-based attacks.
- Organizations should consider the impact of these vulnerabilities on supply chain risk management and vendor due diligence processes.
- Cybersecurity service providers can leverage this development to offer enhanced security assessments and remediation services tailored to software supply chain risks.

**Jurisdictions:** federal
**Industries:** Information Technology
**Topics:** Cybersecurity, Cloud Services
**Published:** June 28, 2026

### Vendors
- Microsoft (affected organization)
- Google (affected organization)
- Cloudflare (affected organization)
- Apache (affected organization)
- Amazon (cloud service provider)

### Key Quotes
> Amazon Q flaw let booby-trapped Git repos execute code, swipe cloud creds
> — Original poster

### Sources
- [Cordyceps CI/CD Weakness Exposes Software Supply Chains to Malicious Pull Requests - Security Boulevard](https://securityboulevard.com/2026/06/cordyceps-ci-cd-weakness-exposes-software-supply-chains-to-malicious-pull-requests) - Security Boulevard
- [Amazon Q flaw let booby-trapped Git repos execute code, swipe cloud creds](https://www.reddit.com/r/cybersecurity/comments/1uhwguq/amazon_q_flaw_let_boobytrapped_git_repos_execute) - reddit-cybersecurity