Skip to content
Threat Feed

Tag

Devops

6 briefs RSS
high threat

TraderTraitor Campaign Targeting DevOps Engineers via Weaponized Terraform Repositories

North Korean threat actor TraderTraitor is using fake job interview lures on GitHub containing weaponized Terraform lock files to deliver macOS backdoors to DevOps engineers, facilitating cloud credential theft.

Terraform TraderTraitor macos supply-chain social-engineering cloud-security devops
4t 5i
high threat

Slim Spider Targets Brazilian Financial Institutions via Cloud Infrastructure

Slim Spider is a financially motivated actor targeting Brazilian financial organizations by stealing cloud credentials and manipulating DevOps pipelines to gain unauthorized access to digital asset custody systems and payment infrastructure.

Azure DevOps +1 Slim Spider financial-crime cloud-security devops credential-theft kubernetes
5t
critical advisory

Nginx-UI Unauthenticated Remote Code Execution via Backup Restore

Nginx-UI is vulnerable to unauthenticated remote code execution (RCE) via the `POST /api/restore` endpoint, allowing attackers to inject arbitrary commands into the configuration.

nginx-ui rce authentication bypass command injection devops
2r 2t
medium advisory

CircleCI Security Step Disabled Detection

Detection of disabling security steps in CircleCI, potentially indicating an attempt to bypass security controls during the CI/CD process.

CircleCI ci/cd devops security-bypass
2r 1t
low advisory

GitHub Self-Hosted Runner Configuration Changes Detected

Detection of changes to self-hosted runner configurations in GitHub environments can indicate potential impact, discovery, collection, persistence, privilege escalation, initial access, or stealth activities.

GitHub Actions github self-hosted-runner audit-log devops supply-chain
3r 8t
medium advisory

Execution via GitHub Actions Runner

Adversaries compromising GitHub Actions workflows can execute arbitrary commands on runner hosts, leading to code execution, reconnaissance, credential harvesting, or network exfiltration.

github-actions supply-chain execution devops
3r 3t