CI/CD Pipeline Attacks: Hunting Secrets in GitHub Actions

Build pipelines hold credentials to everything, run code from untrusted contributors, and are rarely in scope. That combination is why they get compromised.

2025-11-28 · 4 min · 695 words · lcz

Enumerating Azure AD with ROADtools and AzureHound

Mapping a Microsoft cloud tenant from a single set of valid credentials, and reading the result as an attack graph.

2023-02-18 · 3 min · 545 words · lcz