Advertisement
npm Supply Chain Attacks: Shai-Hulud, Miasma, and CI/CD Compromises
The npm ecosystem faces escalating supply chain attacks like Shai-Hulud and Miasma RAT, leading to credential theft and widespread package compromise.
CVE-2026-63077: JetBrains TeamCity Unauthenticated RCE Mitigation Guide
JetBrains has disclosed a critical RCE vulnerability (CVE-2026-63077) in TeamCity On-Premises. Learn how to patch your CI/CD environment and detect exploit attempts.
GitHub Actions Attack Patterns Evade CI Security Scanners
Learn how sophisticated GitHub Actions attack patterns bypass traditional CI security scanners, exposing CI/CD pipelines to supply chain risks.
Cordyceps: Defending Against Malicious Pull Requests in CI/CD
The Cordyceps campaign highlights critical CI/CD vulnerabilities in GitHub Actions, targeting high-profile projects like Apache Doris and Cloudflare Workers SDK.
Novo Nordisk Breach: Securing Secrets in GitHub Development Pipelines
Analysis of the Novo Nordisk GitHub token leak and why secrets management must transition from static tools to identity-based security frameworks.
Anthropic Claude Code GitHub Action Flaw Enables Repo Hijacking
A critical flaw in Anthropic's Claude Code GitHub Action allowed attackers to hijack public repositories using malicious issues, posing supply chain risks.
Advertisement
Megalodon Campaign: 5,561 GitHub Repos Hit by Malicious Workflows
Automated Megalodon attack pushes 5,718 malicious commits to GitHub repositories to exfiltrate secrets via GitHub Actions workflows.
Developer Workstations: The New Front in Software Supply Chain Attacks
A surge in attacks targeting npm, PyPI, and Docker Hub highlights a shift toward stealing developer credentials and API keys from workstations and CI/CD pipelines.
Checkmarx Jenkins AST Plugin Compromised in TeamPCP Attack
TeamPCP compromised the Checkmarx Jenkins AST plugin on the Jenkins Marketplace. Defenders must revert to version 2.0.13 to secure CI/CD pipelines.
Defending CI/CD Pipelines with Build Application Firewalls
Examine how Build Application Firewalls (BAF) provide runtime protection for software pipelines to mitigate sophisticated supply chain attacks and data theft.
Gemini CLI Critical RCE Fix: Patching the @google/gemini-cli Flaw
Google patches a CVSS 10.0 flaw in Gemini CLI tools that allowed unprivileged attackers to execute commands in CI/CD environments via malicious configurations.
CI/CD Pipeline Backdoors: Analyzing Recent Supply Chain Attacks
Exploration of supply chain risks in CI/CD pipelines, IoT device exploitation trends, and the security implications of government data acquisition.
Trivy Supply Chain Attack: TeamPCP Pushes Infostealer via GitHub
Threat actor TeamPCP compromised the Trivy-action repository to distribute infostealer malware through GitHub Actions, targeting CI/CD pipelines and secrets.
SANDWORM_MODE: Malicious npm Cluster Automates Secret Harvesting and Crypto Theft
Security researchers have identified a coordinated campaign involving 19 malicious npm packages designed to exfiltrate CI/CD secrets, API tokens, and private…