Videos / Defcon / Elad Pticha and Oreen Livni: Why Your CI/CD Pipeline Is Vulnerable — and It’s Not Your Fault

Elad Pticha and Oreen Livni: Why Your CI/CD Pipeline Is Vulnerable — and It’s Not Your Fault

Duration: 25min 44sec Type: Presentation (lecture) Playlist: 82 of 146 in Defcon
A DEF CON 32 talk exploring how a single command injection vulnerability in a CI/CD component can put a major open-source project at risk — demonstrated through Bazel and a GitHub Action case study.

The speakers show how even “secure” pipelines can be compromised, demonstrate real attack scenarios, and explain how threat actors can inject malicious code into widely used repositories.