dogear

enter for all results · esc to close

Hacking GitHub AWS integrations again

dagrz.comsite

Attacking misconfigured pipelines that use OIDC.

from
CI/CD Attacks
added
2026-10-10
likes
0

similar

  1. Vulnerable GitHub Actions Workflows Part 1: Privilege Escalation Inside Your CI/CD Pipeline legitsecurity.com

    GitHub Actions workflow_run PE.

  2. How We Discovered Vulnerabilities in CI/CD Pipelines of Popular Open-Source Projects cycode.com

    Extracting all repository and organization secrets in GitHub Actions.

  3. How I hacked into Google's internal corporate assets observationsinsecurity.com

    More ways to find dependencies in code for Dependency Confusion.

  4. PR sneaking github.com

    Methods of sneaking malicious code into GitHub pull requests.

  5. Fixing typos and breaching microsoft's perimeter johnstawinski.com

    Bypass GitHub workflow approval requirement by becoming a contributor.

  6. The (In)security Landscape of AI-Powered GitHub Actions (Part 2/2) wiz.io

    Vulnerabilities in AI-powered GitHub Actions. Syntactical permission checks that let attackers impersonate trusted apps and Dependabot Deputy Confusion Injection.

CI/CD Attacks › Techniques > Initial Code Execution: “Attacking misconfigured pipelines that use OIDC.”