CI/CD Attacks
88 items from tupletype/awesome-cicd-attacks ★634
-
zizmorcore/zizmor github.com
[zizmor] - Static analysis tool for GitHub Actions that finds security issues including template injection, credential leakage, excessive permissions, and impostor commits.
-
-
-
Secrets Patterns Database github.com
The largest open-source database for detecting secrets, API keys, passwords, tokens, and more.
-
-
Common Threat Matrix for CI/CD Pipeline github.com
-
-
Jenkins Attack Framework github.com
This tool can manage Jenkins tasks, like listing jobs, dumping credentials, running commands/scripts, and managing API tokens.
-
-
-
GitHub Actions Attack Diagram github.com
Includes public vulnerability research presented at Black Hat USA 2024 and DEF CON 32.
-
SDLC Infrastructure Threat Framework (SITF) github.com
A comprehensive framework for analyzing and defending against attacks targeting Software Development Life Cycle Infrastructure.
-
Living off the pipeline github.com
Inventory how development tools (typically CLIs), have lesser-known RCE-By-Design features.
-
GitLab Secrets github.com
A tool that can reveal deleted GitLab commits that potentially contain sensitive information and are not accessible via the public Git history.
-
ActionsTOCTOU (Time Of Check to Time Of Use) github.com
A tool to monitor for an approval event and then quickly replace a file in the PR head with a local file specified as a parameter.
-
-
-
-
Remove evidence of malicious pull requests on GitHub x.com
Changing account's email to block-listed domain, automatically bans the account.
-
The (In)security Landscape of AI-Powered GitHub Actions (Part 2/2) wiz.io
Vulnerabilities in AI-powered GitHub Actions. Syntactical permission checks that let attackers impersonate trusted apps and Dependabot Deputy Confusion Injection.
-
Millions of Secrets Exposed via Web Application Frontends web.archive.org
Millions of secrets exposed in web app frontends via JavaScript and debug pages.
-
Can you trust ChatGPT's package recommendations? vulcan.io
Exploit generative AI platforms' tendency to generate non-existent coding libraries to execute Dependecy Confusion.
-
WordPress Plugin Confusion: How an update can get you pwned vavkamil.cz
Unclaimed WordPress plugins are vulnerable to takeover via the plugin directory.
-
#redteam tip: want to discretely extract credentials from a CI/CD pipeline? twitter.com
Draft pull requests won't alert repository contributors, but will still trigger pipelines.
-
(The) Postman Carries Lots of Secrets trufflesecurity.com
Postman's public API network leaks thousands of secrets due to confusing UI, forks, and insufficient secret scanning.
-
Anyone can Access Deleted and Private Repository Data on GitHub trufflesecurity.com
As long as it's part of a fork network.
-
Trojan Source trojansource.codes
Rather than inserting logical bugs, adversaries can attack the encoding of source code files to inject vulnerabilities.
-
Thousands of npm accounts use email addresses with expired domains therecord.media
Maintainer Email hijacking.
-
Hijacking GitHub runners to compromise the organization synacktiv.com
Registering a GitHub runner with the ubuntu-latest tag grants access to jobs originally designated for GitHub-provisioned runners.
-
- next page of items loading…