CI/CD Pipeline Attacks: Hunting Secrets in GitHub Actions

Build pipelines hold credentials to everything, run code from untrusted contributors, and are rarely in scope. That combination is why they get compromised.

2025-11-28 · 4 min · 695 words · lcz

XZ Utils Backdoor (CVE-2024-3094): A Supply Chain Post-Mortem

A near-miss that would have put a backdoor in sshd across major Linux distributions, undone by a curious engineer noticing sshd was 500ms slower.

2024-04-05 · 4 min · 665 words · lcz

Log4Shell (CVE-2021-44228): Exploitation, Detection, and Mitigation

A week after disclosure, what we knew about the Log4j JNDI flaw, why the blast radius was so large, and how to find affected systems.

2021-12-15 · 3 min · 505 words · lcz