CI/CD Pipeline Attacks: Hunting Secrets in GitHub Actions
Build pipelines hold credentials to everything, run code from untrusted contributors, and are rarely in scope. That combination is why they get compromised.
Build pipelines hold credentials to everything, run code from untrusted contributors, and are rarely in scope. That combination is why they get compromised.
Mapping a Microsoft cloud tenant from a single set of valid credentials, and reading the result as an attack graph.