SAML roulette: the hacker always wins
Introduction In this post, we’ll show precisely how to chain round-trip attacks and namespace confusion to achieve unauthenticated admin access on GitLab Enterprise by exploiting the ruby-saml library

4276 articles
4276 ARTICLES
Introduction In this post, we’ll show precisely how to chain round-trip attacks and namespace confusion to achieve unauthenticated admin access on GitLab Enterprise by exploiting the ruby-saml library



How to protect sensitive data in cloud-hosted databases with built-in security controls, best practices, and continuous risk monitoring.

Discover practical steps to create a culture of secure coding, empowering developers to build resilient software and prevent costly vulnerabilities. Insights from Snyk.

Tired of endless security alerts? Snyk Delta Findings in the IDE helps developers cut through the noise and focus on new vulnerabilities introduced in their code. Reduce vulnerability fatigue and ship secure software faster. Get started for free!

The world is at an inflection point in open source software delivery. See where the software distribution status quo is at, and what is next.

tj-actions/changed-files に対するサプライチェーン攻撃により、多くのリポジトリが週末に機密情報を漏えいしました。Wiz Research は、reviewdog/actions-setup@v1 に対する追加のサプライチェーン攻撃を発見しており、これが tj-actions/changed-files の侵害に寄与した可能性があります。

A critical security exploit in the popular GitHub Action changed-files (tj-actions/changed-files) exposed encrypted secrets in plaintext within GitHub Action logs. This vulnerability, affecting over 23,000 repositories, was enabled by orphaned commits and manipulated release tags. Learn how to protect your GitHub workflows from similar exploits.

Chainguard’s defense in depth approach to security helped protect it from the recent tj-actions/changed-files GitHub repository compromise. Learn more about how.

A supply chain attack on popular GitHub Action tj-actions/changed-files caused many repositories to leak their secrets. Discover how it unfolded and the steps to mitigate the risk.

Learn how to manage AI risks effectively with best practices, frameworks, and strategies to ensure secure AI adoption while mitigating vulnerabilities.

Discover best practices for responding to security alerts and remediating vulnerabilities early, reducing security toil, and improving DevSecOps efficiency.
Cookies
We use analytics cookies (Google Analytics) to improve this site. Accept to allow them. Privacy Policy