Artwork

Indhold leveret af Open Source Security and Josh Bressers. Alt podcastindhold inklusive episoder, grafik og podcastbeskrivelser uploades og leveres direkte af Open Source Security and Josh Bressers eller deres podcastplatformspartner. Hvis du mener, at nogen bruger dit ophavsretligt beskyttede værk uden din tilladelse, kan du følge processen beskrevet her https://da.player.fm/legal.
Player FM - Podcast-app
Gå offline med appen Player FM !

tj-actions with Endor Lab's Dimitri Stiliadis

32:39
 
Del
 

Manage episode 479477494 series 1502626
Indhold leveret af Open Source Security and Josh Bressers. Alt podcastindhold inklusive episoder, grafik og podcastbeskrivelser uploades og leveres direkte af Open Source Security and Josh Bressers eller deres podcastplatformspartner. Hvis du mener, at nogen bruger dit ophavsretligt beskyttede værk uden din tilladelse, kan du følge processen beskrevet her https://da.player.fm/legal.

Dimitri Stiliadis, CTO from Endor Labs, discusses the recent tj-actions/changed-files supply chain attack, where a compromised GitHub Action exposed CI/CD secrets. We explore the impressive multi-stage attack vector and the broader often-overlooked vulnerabilities in our CI/CD pipelines, emphasizing the need to treat these build systems with production-level security rigor instead of ignoring them.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-04-tjactions_with_dimitri_stiliadis/

  continue reading

506 episoder

Artwork
iconDel
 
Manage episode 479477494 series 1502626
Indhold leveret af Open Source Security and Josh Bressers. Alt podcastindhold inklusive episoder, grafik og podcastbeskrivelser uploades og leveres direkte af Open Source Security and Josh Bressers eller deres podcastplatformspartner. Hvis du mener, at nogen bruger dit ophavsretligt beskyttede værk uden din tilladelse, kan du følge processen beskrevet her https://da.player.fm/legal.

Dimitri Stiliadis, CTO from Endor Labs, discusses the recent tj-actions/changed-files supply chain attack, where a compromised GitHub Action exposed CI/CD secrets. We explore the impressive multi-stage attack vector and the broader often-overlooked vulnerabilities in our CI/CD pipelines, emphasizing the need to treat these build systems with production-level security rigor instead of ignoring them.

The show notes and blog post for this episode can be found at https://opensourcesecurity.io/2025/2025-04-tjactions_with_dimitri_stiliadis/

  continue reading

506 episoder

كل الحلقات

×
 
Loading …

Velkommen til Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Hurtig referencevejledning

Lyt til dette show, mens du udforsker
Afspil