Category index

Cyber Security

4276 articles

4276 ARTICLES

FEATURED REPORT

SAML roulette: the hacker always wins

Introduction In this post, we’ll show precisely how to chain round-trip attacks and namespace confusion to achieve unauthenticated admin access on GitLab Enterprise by exploiting the ruby-saml library

BY
MIN READ 1 MIN READ
EXPLORE north_east
SAML roulette: the hacker always wins
新たなGitHub Actionのサプライチェーン攻撃: reviewdog/action-setup
CYBERSECURITY

新たなGitHub Actionのサプライチェーン攻撃: reviewdog/action-setup

tj-actions/changed-files に対するサプライチェーン攻撃により、多くのリポジトリが週末に機密情報を漏えいしました。Wiz Research は、reviewdog/actions-setup@v1 に対する追加のサプライチェーン攻撃を発見しており、これが tj-actions/changed-files の侵害に寄与した可能性があります。

1 MIN READ arrow_forward
Reconstructing the TJ Actions Changed Files GitHub Actions Compromise
CYBERSECURITY

Reconstructing the TJ Actions Changed Files GitHub Actions Compromise

A critical security exploit in the popular GitHub Action changed-files (tj-actions/changed-files) exposed encrypted secrets in plaintext within GitHub Action logs. This vulnerability, affecting over 23,000 repositories, was enabled by orphaned commits and manipulated release tags. Learn how to protect your GitHub workflows from similar exploits.

1 MIN READ arrow_forward
An Ode to Defense in Depth
CYBERSECURITY

An Ode to Defense in Depth

Chainguard’s defense in depth approach to security helped protect it from the recent tj-actions/changed-files GitHub repository compromise. Learn more about how.

1 MIN READ arrow_forward