Paul SerbanSoftware Engineer
  • PORTFOLIO
  • BLOG

#Remote Code Execution

Posts

  • From Fork to RCE: Deconstructing the Orca Security GitHub Actions ExploitFollowing the attacker's path, from creating a malicious fork to exfiltrating API keys and pushing code to protected branches.

    A step-by-step breakdown of the 'Pull Request Nightmare' exploit. See how attackers leverage `pull_request_target` to achieve RCE and steal secrets.

    • #GitHub Actions
    • #CI/CD Security
    • #DevSecOps
    • #Supply Chain Attacks
    • #Orca Security
View all posts
  • LinkedInLinkedIn
  • GitHubGitHub
  • HackerRankHackerRank
  • LeetCodeLeetCode
  • EmailEmail
  • Portfolio
  • My Projects
  • Coursework
  • Blog
  • Posts
  • Snippets
  • Book Notes
  • Cookie Settings
  • Cookie Policy
2025 © Paul Serban. All rights reserved.www.paulserban.eu | Sitemap