Elad Pticha and Oreen Livni: Why Your CI/CD Pipeline Is Vulnerable — and It’s Not Your Fault
A DEF CON 32 talk exploring how a single command injection vulnerability in a CI/CD component can put a major open-source project at risk — demonstrated through Bazel and a GitHub Action case study.
The speakers show how even “secure” pipelines can be compromised, demonstrate real attack scenarios, and explain how threat actors can inject malicious code into widely used repositories.
The speakers show how even “secure” pipelines can be compromised, demonstrate real attack scenarios, and explain how threat actors can inject malicious code into widely used repositories.