Class Central is learner-supported. When you buy through links on our site, we may earn an affiliate commission.

YouTube

How Hackers Can Breach CI/CD Systems - Security Vulnerabilities and Mitigation

OWASP Foundation via YouTube

Overview

Google, IBM & Meta Certificates – 40% Off
One Coursera Plus subscription covers most Professional Certificates on Coursera.
Unlock All Certificates
This talk examines common security flaws in CI/CD environments and demonstrates how they can be exploited to gain control of an organization’s production systems. It also discusses mitigation through demonstrations using commonly used CI/CD components.

Syllabus

Intro
CONTINUOUS DELIVERY CONTINUOUS DEPLOYMENT
The IDE Leaks!
The BAD ROLE Granularity!
The DEV Machine as only source code se
All Libraries Allowed!
SECRETS & LEAKS
Control Artefacts Repository
The ENVIRONMENT Leak! (1/2)
The ENV Leak! (2/2)
A reverse Shell in the Pipeline
The Evil GitHub Actions!
The mighty CI BOT
The EVIL AGENT (1/3)
The EVIL AGENT (3/3)
The DOCKER HUB Leak!
Keep API Safe!
The SOURCE CODE ransomware!
The Fat DOCKER!
The evil DOCKER twin!
The Greedy Service consumer!
Run FREE Internet!
The Trojan Jar!
The ZIP BOMB (2/4)
The ZIP BOMB (4/4)
Memory BOMB (3/5)
Memory BOMB (5/5)
Fork BOMB! (1/2)
Is your API Honest!? (1/2)
Keep SECRETS safe!
The Evil Alias!
The Shared infra! (1/2)
The TIP Of the iceberg

Taught by

OWASP Foundation

Reviews

Start your review of How Hackers Can Breach CI/CD Systems - Security Vulnerabilities and Mitigation

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.