← Back to feed
research Elastic Security Labs

CI/CD pipeline abuse: the problem no one is watching

Elastic Security Labs Microsoft

How we built an open-source, drop-in CI template that uses signal extraction and LLM reasoning to catch CI/CD abuse in GitHub Actions, GitLab CI, and Azure D...

Read the full story Elastic Security Labs →

Related Coverage

research SAML: A fractal of bad design Trail of Bits · Sep 21 research Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO Kaspersky Securelist · Sep 21 research From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies Unit 42 · Sep 21