Skip to main content
← All Articles

Tag

#CI

5 articles

Advertisement

Cordyceps CI/CD Flaws: Supply Chain Attacks on GitHub Repositories
CRITICAL
Supply Chain

Cordyceps CI/CD Flaws: Supply Chain Attacks on GitHub Repositories

Novee Security uncovered Cordyceps, a critical CI/CD workflow flaw exposing over 300 GitHub repositories to supply chain compromise, affecting major organizations.

Runtime Rebel Intel
4 min read·Jun 24, 2026
JINX-0164 Targets Crypto Firms with macOS Malware and Fake Lures
HIGH
Threat Intel

JINX-0164 Targets Crypto Firms with macOS Malware and Fake Lures

The JINX-0164 threat actor targets cryptocurrency firms via recruitment-themed social engineering, macOS-specific malware, and CI/CD infrastructure exploits.

Runtime Rebel Intel
3 min read·May 28, 2026
SU
CRITICAL
Supply Chain

Axios NPM Supply Chain Attack Bypasses GitHub Actions CI/CD

A sophisticated supply chain attack targeted the Axios NPM package, leveraging a compromised token to bypass GitHub Actions CI/CD and deploy malicious versions.

Runtime Rebel Intel
4 min read·Apr 1, 2026
Trivy Supply Chain Attack Targets CI/CD Secrets in DevOps Workflows
HIGH
Supply Chain

Trivy Supply Chain Attack Targets CI/CD Secrets in DevOps Workflows

A supply chain attack leveraged the Trivy security tool to deploy an infostealer within CI/CD pipelines, compromising cloud credentials and sensitive secrets.

Runtime Rebel Intel
4 min read·Mar 24, 2026
TH
INFO
Threat Intel

Proactive Defense: Hardening Against Destructive Cyberattacks (2026 Edition)

Comprehensive guide on hardening against destructive cyberattacks, including wipers, ransomware, and data destruction tactics across on-premises and cloud environments.

Runtime Rebel Intel
12 min read·Mar 6, 2026