
Code to Cloud Attacks: From Github PAT to Cloud Control Plane
How attackers are leveraging compromised employee GitHub Personal Access Tokens to compromise cloud environments.
3830 articles

How attackers are leveraging compromised employee GitHub Personal Access Tokens to compromise cloud environments.

Snyk helps Federal Agencies secure software for the White House’s Genesis Mission, accelerating AI-driven science. Implement Secure by Design for the supply chain, cloud, and pipelines.

Chainguard now offers hardened, zero-CVE MCP container images, starting with mcp-grafana, with more on the way.

Explore all the latest features and releases for Chainguard Containers and Chainguard Libraries.

The re:Invent announcements that are most impactful to security teams.

Nathan Parker from the Chrome security team outlines the advancements made in browser security due to the introduction of agentic capabilities in Chrome, particularly concerning the risks of indirect prompt injection. To address these threats, Google has developed a layered defense strategy that includes features like the User Alignment Critic, which reviews actions for user alignment and protects against goal-hijacking. Enhanced origin isolation limits the data agents can access, while user confirmations ensure control over critical actions. Continuous monitoring and collaboration with the security community are emphasized as essential to maintaining safety amid evolving challenges.

We break down the exploit mechanics and detail active in-the-wild attacks observed by our team, from credential harvesting to sophisticated cloud backdoors.

See how we give engineers protected space for self-directed, high-impact work; boosting innovation and improving engineering morale.



Learn how we keep Chainguard OS and Wolfi lean and secure with automated package garbage collection that cuts attack surface while preserving reproducibility.

Customers can now leverage Anchore Enterprise’s scanning capabilities for Chainguard Libraries for Python.