JFrog's AI-powered security research bot, RepoHunter, proactively identified 13 critical CI/CD vulnerabilities across major open-source projects including Ansible, QGIS, Telepresence, and TC39 JavaScript proposals. The vulnerabilities stem from 'Pwn Request' patterns where GitHub Actions workflows using pull_request_target

15m read time From jfrog.com
Post cover image
Table of contents
Why CI/CD is the New TargetWhat Is a “Pwn Request” / GitHub Actions CI Takeover?RepoHunter: Hunting CI Takeovers Before They ScaleFour Phases of a CI Supply Chain AttackRepoHunter CI\CD Takeover SummaryHypothetical Example: A Shai-Hulud-Style CI WormVulnerability Deep Dive: Ansible PlatformConclusion – Securing CI as Critical Infrastructure

Sort: