Cybersecurity firm Novee has uncovered a critical class of vulnerabilities dubbed Cordyceps that exposes millions of repositories to complete takeover through flawed CI/CD workflows. The security defects, found in GitHub Actions and similar systems, allow unauthenticated attackers to hijack developer workflows, forge approvals, and steal credentials, with confirmed impacts on major projects from Microsoft, Google, Apache, Cloudflare, and the Python Software Foundation. Novee warns that AI-driven code generation has accelerated the spread of these insecure patterns, with hundreds of repositories confirmed fully exploitable in a single scan, potentially affecting thousands of downstream organizations that depend on these compromised repositories.