Tag

#CI/CD

6 published stories tagged with CI/CD.

criticalExploited VulnerabilitiesJul 28, 20262 min read

Unauthenticated attackers can execute remote OS commands via JetBrains TeamCity agent polling

馃毃 Critical unauthenticated remote code execution flaw found in JetBrains TeamCity. Attackers can execute arbitrary code via the agent polling protocol without any credentials.

highSupply Chain SecurityJun 2, 20266 min read

Red Hat Cloud Services npm Compromise Shows How Trusted Frontend Packages Can Become A Build Pipeline Risk

Red Hat says a supply chain compromise affected multiple packages in the `@redhat-cloud-services` npm namespace after a compromised GitHub account pushed unauthorized commits.

highSupply Chain SecurityMay 8, 20264 min read

Brief: Trivy supply chain attack targets CI/CD secrets

Dark Reading reported a Trivy-related supply-chain attack targeting CI/CD secrets. Pipeline secrets should be scoped, rotated, monitored, and protected from untrusted build steps.

highSupply Chain SecurityMay 8, 20264 min read

Defender Guidance: Trivy supply chain attack targets CI/CD secrets

Dark Reading reported a Trivy-related supply-chain attack targeting CI/CD secrets. Pipeline secrets should be scoped, rotated, monitored, and protected from untrusted build steps.

highSupply Chain SecurityMay 8, 20264 min read

Detection Notes: Trivy supply chain attack targets CI/CD secrets

Dark Reading reported a Trivy-related supply-chain attack targeting CI/CD secrets. Pipeline secrets should be scoped, rotated, monitored, and protected from untrusted build steps.

highSupply Chain SecurityMay 8, 20264 min read

Risk Brief: Trivy supply chain attack targets CI/CD secrets

Dark Reading reported a Trivy-related supply-chain attack targeting CI/CD secrets. Pipeline secrets should be scoped, rotated, monitored, and protected from untrusted build steps.