Introducing Raven: CI/CD Pipeline Security with Open Source Vulnerability Scanner Starting with GitHub Actions
Cycode is proud to announce the public release of Raven…
Schedule a 30-minute live product demo with expert Q&A
Cycode is proud to announce the public release of Raven…
Exposed credentials are one of the most abused methods for gaining initial access…
This is the full story of the vulnerability we have discovered within Visual Studio Code (VS Code) concerning the handling of secure token storage. While designed for isolated storage for each extension, this vulnerability presents…
GitLab, has recently patched a critical vulnerability that allows attackers to attach malicious runners…
As the demand for faster and more efficient application deployment grows, the use of pipelines…
As part of our ongoing research in the open-source ecosystem, Cycode Labs has found and disclosed a novel attack…
Cycode Labs discovered a vulnerability in Github’s API in which GitHub Actions workflows …
Securing open-source projects is hard. Securing CI workflows…
Cycode found several vulnerabilities in its GitHub Actions development pipeline that may have allowed any user on the internet to run arbitrary code …
Every software manufacturer nowadays implements robust DevOps processes to increase its ability to deliver applications and services at high velocity. These processes usually include testing, building, packaging, deploying, and additional autonomous procedures. This article will demonstrate that the race to embrace CI/CD capabilities has introduced subtle new risks. An especially significant risk that most organizations … Read more