Tag

#CI/CD

7 stories taggedCI/CD.

Cloud Security

Detection Engineering Grew Up. Most Security Stacks Didn't.

Behavior-based, CI/CD-integrated detection logic is eating vendor-supplied rules. Here's what's actually driving the shift — and what teams still get wrong.

3 min read
AI Security

Bash Shell Tricks From the '90s Are Breaking AI Coding Agents Wide Open

Old-school shell injection techniques can bypass safeguards in most open-source AI coding agents — and a poisoned repo is all it takes to start the chain.

2 min read
Threat Intelligence

GlassWorm Is Down. The Repository Problem Isn't.

CrowdStrike, Google, and Shadowserver severed four C2 channels simultaneously. Meanwhile, 157 OSV false positives quietly eroded trust in the tools defenders depend on.

3 min read
Threat Intelligence

Megalodon Campaign Pushed 5,718 Malicious Commits Into GitHub Repos in Six Hours

An automated backdooring operation abused compromised GitHub credentials to silently inject base64-encoded bash payloads into CI/CD workflows across more than 5,500 public repositories on May 18.

2 min read
AI Security

Microsoft Open-Sources Rampart and Clarity to Embed AI Agent Safety Into Dev Pipelines

Two new tools shift AI red-teaming left, targeting prompt injection and privilege escalation before code ships.

3 min read
AI Security

AI Governance Is Broken Because It Still Lives Outside the Pipeline

Building compliance as a post-ship review layer made sense for static software. For AI systems that mutate overnight, it is organizational negligence dressed up as process.

3 min read
Threat Intelligence

TrapDoor: The Supply Chain Campaign That Wants Your Whole Dev Environment, Not Just Your Secrets

A cross-registry malware campaign hitting npm, PyPI, and Crates.io is going after CI/CD pipelines, SSH trust chains, and AI coding assistant files — not just credentials on install.

3 min read
© 2026 Threat Vectr