Hackerbot-Claw GitHub Actions Exploitation Campaign
Recon and Workflow Discovery Hackerbot-claw identified Trivy's vulnerable pull_request_target workflow ("API Diff Check"), which checked out PR code and used a PAT with broad permissions, not only the ephemeral GITHUB_TOKEN. Initial Access via PR and CI Execution The bot forked aquasecurity/trivy and