Tag: CI/CD security
GitHub and PyPI Bet On Time to Slow Down Software Supply Chain Attacks
GitHub and PyPI are using time as a security control, delaying dependency updates and locking older releases against new file uploads ...
The Trust Graph: Why Infrastructure Diagrams No Longer Describe Modern Systems
Traditional architecture diagrams miss the identity relationships that now drive breaches and outages. Platform teams need trust graphs that map who and what can act across modern systems ...
Zero Trust Starts at the Code: Building Secure Systems with PKI and DevOps Automation
When a certificate expires, it can take down a production system, and teams usually only find out after something goes wrong. These issues are hard to catch because they rarely trigger alerts ...
Why Developer Workstations Have Become a Critical Part of the Software Supply Chain
For years, software supply-chain security discussions focused on centralized infrastructure such as build servers, package registries, and CI/CD systems. Recent attacks suggest that this view is incomplete. The Megalodon campaign injected malicious ...
Novee Uncovers Cordyceps: The Latest Threat to CI/CD Pipelines
A newly discovered supply chain security flaw is once again putting a spotlight on inherent weaknesses in CI/CD pipelines and the growing interest among cyberthreat actors to exploit them. Security researchers with ...
Why Endpoint Protection Matters More than Ever in CI/CD Environments
CI/CD environments depend on far more than repositories and deployment infrastructure. Developer endpoints hold sensitive data: cloud credentials, SSH keys, deployment permissions, direct access to internal systems. Endpoint security and control are ...
Shift Left to the Developer’s Machine: Building Local Git Security Gates
Shift left to the developer's machine. The principle is what matters: Stop secrets before they ship. The tooling is a means to that end. ...
Agentic DevSecOps: AI Security Co-Pilots for Your CI/CD Pipeline
The emergence of AI has brought endless possibilities and innovative opportunities in today’s ever-changing, fast-paced technology landscape. AI is helping development teams produce software significantly faster than ever before. AI-enabled DevSecOps tools ...
Widespread Mini Shai-Hulud Campaign Is a Matter of Trust
The latest series of attacks using the notorious Shai-Hulud worm puts into sharp focus the threats facing software developers and their CI/CD pipelines, an issue that has been raised in recent months ...
Your CI/CD Pipeline Has Non-Human Identities You Forgot About
A deployment starts failing late on a Friday evening. The initial assumption is that something changed in the application release. Teams start checking container images, Terraform plans and recent commits. Nothing looks ...
AI-Generated Apps Without DevOps: A Security Disaster Waiting to Happen
A small internal tool was built over a weekend. An engineer used an AI coding assistant to generate most of the backend. A simple interface was added, a few API calls were ...
AWS CodeBuild Webhook Misconfiguration Exposed Admin Access Risk
AWS fixed webhook filter misconfigurations in CodeBuild that could have allowed unauthorized repository access. No customer impact or malicious code found ...

