<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #CI CD Security</title><description>Cybersecurity articles tagged #CI CD Security on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>npm Supply Chain Attacks: Shai-Hulud, Miasma, and CI/CD Compromises</title><link>https://runtimerebel.com/blog/npm-supply-chain-attacks-shai-hulud-miasma-and-ci-cd-compromises</link><guid isPermaLink="true">https://runtimerebel.com/blog/npm-supply-chain-attacks-shai-hulud-miasma-and-ci-cd-compromises</guid><description>The npm ecosystem faces escalating supply chain attacks like Shai-Hulud and Miasma RAT, leading to credential theft and widespread package compromise.</description><pubDate>Sat, 08 Aug 2026 16:26:28 GMT</pubDate><category>NPM</category><category>Supply Chain Attack</category><category>Shai Hulud</category><category>TeamPCP</category><category>CI CD Security</category></item><item><title>CVE-2026-63077: JetBrains TeamCity Unauthenticated RCE Mitigation Guide</title><link>https://runtimerebel.com/blog/cve-2026-63077-jetbrains-teamcity-unauthenticated-rce-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2026-63077-jetbrains-teamcity-unauthenticated-rce-mitigation-guide</guid><description>JetBrains has disclosed a critical RCE vulnerability (CVE-2026-63077) in TeamCity On-Premises. Learn how to patch your CI/CD environment and detect exploit attempts.</description><pubDate>Tue, 28 Jul 2026 10:36:59 GMT</pubDate><category>CVE-2026-63077</category><category>JetBrains</category><category>TeamCity</category><category>RCE</category><category>CI CD Security</category></item><item><title>GitHub Actions Attack Patterns Evade CI Security Scanners</title><link>https://runtimerebel.com/blog/github-actions-attack-patterns-evade-ci-security-scanners</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-actions-attack-patterns-evade-ci-security-scanners</guid><description>Learn how sophisticated GitHub Actions attack patterns bypass traditional CI security scanners, exposing CI/CD pipelines to supply chain risks.</description><pubDate>Tue, 07 Jul 2026 14:38:51 GMT</pubDate><category>GitHub Actions</category><category>CI CD Security</category><category>Supply Chain Security</category><category>Security Scanning</category><category>Code Integrity</category></item><item><title>Cordyceps: Defending Against Malicious Pull Requests in CI/CD</title><link>https://runtimerebel.com/blog/cordyceps-defending-against-malicious-pull-requests-in-ci-cd</link><guid isPermaLink="true">https://runtimerebel.com/blog/cordyceps-defending-against-malicious-pull-requests-in-ci-cd</guid><description>The Cordyceps campaign highlights critical CI/CD vulnerabilities in GitHub Actions, targeting high-profile projects like Apache Doris and Cloudflare Workers SDK.</description><pubDate>Wed, 24 Jun 2026 09:23:01 GMT</pubDate><category>GitHub Actions</category><category>CI CD Security</category><category>Supply Chain Attack</category><category>DevSecOps</category><category>Cordyceps</category></item><item><title>Novo Nordisk Breach: Securing Secrets in GitHub Development Pipelines</title><link>https://runtimerebel.com/blog/novo-nordisk-breach-securing-secrets-in-github-development-pipelines</link><guid isPermaLink="true">https://runtimerebel.com/blog/novo-nordisk-breach-securing-secrets-in-github-development-pipelines</guid><description>Analysis of the Novo Nordisk GitHub token leak and why secrets management must transition from static tools to identity-based security frameworks.</description><pubDate>Fri, 19 Jun 2026 09:48:31 GMT</pubDate><category>GitHub</category><category>Secrets Management</category><category>Novo Nordisk</category><category>DevSecOps</category><category>CI CD Security</category></item><item><title>Anthropic Claude Code GitHub Action Flaw Enables Repo Hijacking</title><link>https://runtimerebel.com/blog/anthropic-claude-code-github-action-flaw-enables-repo-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/anthropic-claude-code-github-action-flaw-enables-repo-hijacking</guid><description>A critical flaw in Anthropic&apos;s Claude Code GitHub Action allowed attackers to hijack public repositories using malicious issues, posing supply chain risks.</description><pubDate>Thu, 04 Jun 2026 17:08:52 GMT</pubDate><category>Anthropic</category><category>Claude Code</category><category>GitHub Actions</category><category>CI CD Security</category><category>RyotaK</category></item><item><title>Megalodon Campaign: 5,561 GitHub Repos Hit by Malicious Workflows</title><link>https://runtimerebel.com/blog/megalodon-campaign-5561-github-repos-hit-by-malicious-workflows</link><guid isPermaLink="true">https://runtimerebel.com/blog/megalodon-campaign-5561-github-repos-hit-by-malicious-workflows</guid><description>Automated Megalodon attack pushes 5,718 malicious commits to GitHub repositories to exfiltrate secrets via GitHub Actions workflows.</description><pubDate>Fri, 22 May 2026 12:58:34 GMT</pubDate><category>Megalodon</category><category>GitHub Actions</category><category>CI CD Security</category><category>Supply Chain Attack</category></item><item><title>Developer Workstations: The New Front in Software Supply Chain Attacks</title><link>https://runtimerebel.com/blog/developer-workstations-the-new-front-in-software-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/developer-workstations-the-new-front-in-software-supply-chain-attacks</guid><description>A surge in attacks targeting npm, PyPI, and Docker Hub highlights a shift toward stealing developer credentials and API keys from workstations and CI/CD pipelines.</description><pubDate>Mon, 18 May 2026 13:23:15 GMT</pubDate><category>NPM</category><category>PyPI</category><category>Docker Hub</category><category>CI CD Security</category><category>Credential Theft</category><category>Developer Security</category></item><item><title>Checkmarx Jenkins AST Plugin Compromised in TeamPCP Attack</title><link>https://runtimerebel.com/blog/checkmarx-jenkins-ast-plugin-compromised-in-teampcp-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/checkmarx-jenkins-ast-plugin-compromised-in-teampcp-attack</guid><description>TeamPCP compromised the Checkmarx Jenkins AST plugin on the Jenkins Marketplace. Defenders must revert to version 2.0.13 to secure CI/CD pipelines.</description><pubDate>Mon, 11 May 2026 20:39:30 GMT</pubDate><category>Checkmarx</category><category>Jenkins</category><category>TeamPCP</category><category>Supply Chain Attack</category><category>CI CD Security</category></item><item><title>Defending CI/CD Pipelines with Build Application Firewalls</title><link>https://runtimerebel.com/blog/defending-ci-cd-pipelines-with-build-application-firewalls</link><guid isPermaLink="true">https://runtimerebel.com/blog/defending-ci-cd-pipelines-with-build-application-firewalls</guid><description>Examine how Build Application Firewalls (BAF) provide runtime protection for software pipelines to mitigate sophisticated supply chain attacks and data theft.</description><pubDate>Mon, 11 May 2026 17:01:45 GMT</pubDate><category>BAF</category><category>CI CD Security</category><category>Supply Chain Attack</category><category>Build Time Protection</category><category>Pipeline Security</category></item><item><title>Gemini CLI Critical RCE Fix: Patching the @google/gemini-cli Flaw</title><link>https://runtimerebel.com/blog/gemini-cli-critical-rce-fix-patching-the-google-gemini-cli-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/gemini-cli-critical-rce-fix-patching-the-google-gemini-cli-flaw</guid><description>Google patches a CVSS 10.0 flaw in Gemini CLI tools that allowed unprivileged attackers to execute commands in CI/CD environments via malicious configurations.</description><pubDate>Thu, 30 Apr 2026 08:52:38 GMT</pubDate><category>Google Gemini CLI</category><category>GitHub Actions</category><category>Google Gemini</category><category>CI CD Security</category><category>RCE</category></item><item><title>CI/CD Pipeline Backdoors: Analyzing Recent Supply Chain Attacks</title><link>https://runtimerebel.com/blog/ci-cd-pipeline-backdoors-analyzing-recent-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/ci-cd-pipeline-backdoors-analyzing-recent-supply-chain-attacks</guid><description>Exploration of supply chain risks in CI/CD pipelines, IoT device exploitation trends, and the security implications of government data acquisition.</description><pubDate>Mon, 23 Mar 2026 16:24:41 GMT</pubDate><category>CI CD Security</category><category>Supply Chain Attack</category><category>Iot Security</category><category>Pipeline Backdoor</category></item><item><title>Trivy Supply Chain Attack: TeamPCP Pushes Infostealer via GitHub</title><link>https://runtimerebel.com/blog/trivy-supply-chain-attack-teampcp-pushes-infostealer-via-github</link><guid isPermaLink="true">https://runtimerebel.com/blog/trivy-supply-chain-attack-teampcp-pushes-infostealer-via-github</guid><description>Threat actor TeamPCP compromised the Trivy-action repository to distribute infostealer malware through GitHub Actions, targeting CI/CD pipelines and secrets.</description><pubDate>Sat, 21 Mar 2026 20:08:15 GMT</pubDate><category>Trivy Scanner</category><category>GitHub Actions</category><category>TeamPCP</category><category>Infostealer</category><category>CI CD Security</category></item><item><title>SANDWORM_MODE: Malicious npm Cluster Automates Secret Harvesting and Crypto Theft</title><link>https://runtimerebel.com/blog/sandworm-mode-malicious-npm-cluster-automates-secret-harvesting-and-crypto-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/sandworm-mode-malicious-npm-cluster-automates-secret-harvesting-and-crypto-theft</guid><description>Security researchers have identified a coordinated campaign involving 19 malicious npm packages designed to exfiltrate CI/CD secrets, API tokens, and private…</description><pubDate>Mon, 23 Feb 2026 12:20:23 GMT</pubDate><category>NPM</category><category>Supply Chain Attack</category><category>Credential Harvesting</category><category>CI CD Security</category><category>JavaScript</category></item></channel></rss>