I am excited to be speaking about Open Source Software and Supply Chain Security at the HTAP Summit 2023 tomorrow right after some amazing keynote speeches! ๐Thanks, @NCCGroupplc and @PingCAP for the opportunity! #opensourcesecurity#supplychainsecurity
@NCCGroupplc - Thanks for the opportunity to interview with @MariaKorolov for CSO Magazine, after our blog post on 10 real-world stories of how we have compromised CI-CD Pipelines! Congratulations @wucpi on being featured in the article https://t.co/lokhgW7cfe
@kylekyle Thanks for mentioning the blog post, Kyle! Principle of Least Privilege is important to prevent these problems, right from developer checking in source code repositories to deployment in Clusters. CI-CD Pipelines can definitely be leveraged by attackers for MASSIVE impact.
@CesarTalledo4@nestybox Thanks! Canโt stress enough how many real-world stories of how I have compromised CI-CD Pipelines have privileged Containers as a major flaw. Sysbox container runtime seems promising, definitely.
@davidmytton Yep, only needs 1 misconfiguration setting to get in. :) We have compromised CI-CD Pipelines in several engagements, roughly using these storiesโฆ
There are still seats available for @NCCGroupInfosec's Mastering Container Security training at BlackHat next month. If you want to learn about attacking or defending Docker and K8s, consider signing up! https://t.co/i3E1IEXC8M
Woke up this morning and found a project I worked on is now public. ๐ค๐ฅ While with NCC Group I worked with a team (@0lsen_@ChaosDatumz@divya_natesan) to do a security review the main components of Istio...it's from 8/2020 though. Don't expect 0days.
https://t.co/KOrsdrY5kh