Structured data rendered for: CollectionPage
Back to Blog
7 posts with this tag

#CI/CD Security

7 posts
Vect and TeamPCP show how stolen build secrets become ransomware access

Vect and TeamPCP show how stolen build secrets become ransomware access

Vect and TeamPCP show how stolen build secrets become ransomware access Sophos says two cybercrime groups, Vect and TeamPCP, have formalized a partnership that...

Last updated on 05/07/2026 at 8:07 AM
7 min read
Red Hat npm compromise proves provenance alone is not enough

Red Hat npm compromise proves provenance alone is not enough

Red Hat npm compromise proves provenance alone is not enough Red Hat has confirmed that multiple packages published under the @redhat-cloud-services npm namespa...

Last updated on 17/08/2026 at 12:56 PM
6 min read
GitHub Action tag hijack turns CI/CD runs into credential theft

GitHub Action tag hijack turns CI/CD runs into credential theft

GitHub Action tag hijack turns CI/CD runs into credential theft A fresh GitHub Actions supply chain incident is a good reminder that "pinned" does not mean safe...

Last updated on 17/08/2026 at 12:56 PM
6 min read
Bitwarden CLI npm compromise exposes CI/CD credential risk

Bitwarden CLI npm compromise exposes CI/CD credential risk

Bitwarden CLI npm compromise exposes CI/CD credential risk A brief compromise of the Bitwarden CLI npm distribution is still a high-priority defender story beca...

Last updated on 17/08/2026 at 12:56 PM
5 min read
Cisco Breach Shows the Real Cost of the Trivy Supply-Chain Attack

Cisco Breach Shows the Real Cost of the Trivy Supply-Chain Attack

Cisco Breach Shows the Real Cost of the Trivy Supply-Chain Attack The most important lesson from the Trivy incident is that a supply-chain attack on a trusted s...

Last updated on 01/04/2026 at 6:08 AM
5 min read
Trivy GitHub Action compromise exposed CI/CD secrets in a stealth supply-chain attack

Trivy GitHub Action compromise exposed CI/CD secrets in a stealth supply-chain attack

Trivy GitHub Action compromise exposed CI/CD secrets in a stealth supply-chain attack A supply-chain compromise in Aqua Security’s aquasecurity/trivy-action sho...

Last updated on 22/03/2026 at 7:29 AM
4 min read
Cline CLI 2.3.0 supply chain attack silently installed OpenClaw on developer systems

Cline CLI 2.3.0 supply chain attack silently installed OpenClaw on developer systems

Cline CLI 2.3.0 supply chain attack silently installed OpenClaw on developer systems Executive summary The Cline CLI supply chain incident is a practical remind...

Last updated on 17/08/2026 at 12:55 PM
5 min read