Hacking GitHub AWS integrations again
Attacking misconfigured pipelines that use OIDC.
- from
- CI/CD Attacks
- added
- 2026-10-10
- likes
- 0
similar
-
Vulnerable GitHub Actions Workflows Part 1: Privilege Escalation Inside Your CI/CD Pipeline legitsecurity.com
GitHub Actions workflow_run PE.
-
How We Discovered Vulnerabilities in CI/CD Pipelines of Popular Open-Source Projects cycode.com
Extracting all repository and organization secrets in GitHub Actions.
-
How I hacked into Google's internal corporate assets observationsinsecurity.com
More ways to find dependencies in code for Dependency Confusion.
-
-
Fixing typos and breaching microsoft's perimeter johnstawinski.com
Bypass GitHub workflow approval requirement by becoming a contributor.
-
The (In)security Landscape of AI-Powered GitHub Actions (Part 2/2) wiz.io
Vulnerabilities in AI-powered GitHub Actions. Syntactical permission checks that let attackers impersonate trusted apps and Dependabot Deputy Confusion Injection.
CI/CD Attacks › Techniques > Initial Code Execution: “Attacking misconfigured pipelines that use OIDC.”