<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Pipeline-Integrity - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/pipeline-integrity/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 05 Oct 2026 12:05:45 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/pipeline-integrity/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Detection of Bypassed Mandatory Security Jobs in CircleCI Pipelines</title><link>https://feed.craftedsignal.io/briefs/2026-10-circleci-security-job-bypass/</link><pubDate>Mon, 05 Oct 2026 12:05:45 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-circleci-security-job-bypass/</guid><description>Detection of unauthorized omission of mandatory security jobs within CircleCI workflows which could indicate an attacker attempting to bypass CI/CD pipeline integrity checks.</description><content:encoded><![CDATA[<p>This threat brief addresses the risk of unauthorized modifications to CI/CD pipeline configurations in CircleCI, specifically where mandatory security jobs are omitted or disabled. Attackers targeting the software supply chain may attempt to alter pipeline workflows to bypass automated security testing, such as SAST, DAST, or dependency scanning. By disabling these mandatory jobs, malicious code can be introduced into the development lifecycle without triggering alerts or automated blocks. This analytic identifies such anomalies by monitoring CircleCI logs and validating that required security tasks are executed within every workflow. Detecting this activity is critical for maintaining pipeline integrity and preventing the deployment of compromised artifacts.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>An attacker gains access to the version control system or the CI/CD configuration files (e.g., .circleci/config.yml) associated with the project.</li>
<li>The attacker modifies the workflow configuration to exclude mandatory security or quality assurance jobs.</li>
<li>The attacker pushes the malicious or modified configuration file to the repository.</li>
<li>CircleCI detects the new configuration and triggers the CI/CD pipeline.</li>
<li>The pipeline executes the modified workflow, skipping the required security scanning tasks.</li>
<li>The pipeline completes successfully without performing the necessary security validations.</li>
<li>Malicious code is processed through the pipeline, potentially leading to unauthorized execution or compromised software delivery.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful bypass of security checks in a CI/CD pipeline can lead to the introduction of vulnerabilities or malicious payloads into production environments. This compromise threatens the integrity of the organization's software supply chain, potentially leading to data breaches, system downtime, and severe reputational damage.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Detection engineering teams should monitor CircleCI logs for workflow execution anomalies. Implement the provided logic to track mandatory security jobs against reported execution logs to identify unauthorized workflow modifications.</p>
<ul>
<li>Implement visibility into CircleCI pipeline logs to monitor job execution status.</li>
<li>Review and maintain a strict list of mandatory security jobs that must run in every project workflow.</li>
<li>Investigate any pipeline workflow where a mandatory security job is skipped or absent.</li>
<li>Enforce code signing or branch protection rules in the source control management system to prevent unauthorized modifications to pipeline configuration files.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>ci-cd</category><category>cloud-security</category><category>pipeline-integrity</category></item></channel></rss>