GeistHaus
log in · sign up

Detecting CI/CD Supply Chain Attacks with Canary Credentials | Tracebit

tracebit.com

A single threat actor - TeamPCP - compromised a chain of widely-used open source tools: Trivy, KICS, LiteLLM, and Telnyx. This post looks at the campaign and explores the question: once you've pinned your actions and hardened your runners, what actually detects credential exfiltration from a compromised CI/CD pipeline?

1 page links to this URL