YoVDO

The Dark Playground of CI/CD - Attack Delivery by GitHub Actions

Offered By: BSidesLV via YouTube

Tags

GitHub Actions Courses Threat Modeling Courses Responsible Disclosure Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the potential security vulnerabilities in GitHub Actions, a popular CI/CD feature, through this comprehensive conference talk. Dive into known and unknown attack techniques, including newly discovered vectors such as "Malicious Custom Action" and "GitHub Actions C2". Examine code explanations and live demonstrations of these attacks, and gain insights into threats like "Free Jacking", "Malicious Public PR&Fork", and "Theft of Secret". Learn how researchers systematize these attacks based on GitHub's features and threat levels. Understand the broader implications for other CI/CD services with similar features, and discover how this research contributes to enhancing overall security in the CI/CD landscape. Presented by Yusuke Kubo and Kiyohito Yamamoto, this talk also touches on their collaboration with GitHub for responsible disclosure and countermeasure development.

Syllabus

BG - The Dark Playground of CI/CD: Attack Delivery by GitHub Actions


Taught by

BSidesLV

Related Courses

Ethics in Information Security
LinkedIn Learning
Tech on the Go: Ethics in Cybersecurity
LinkedIn Learning
Advanced Android Studio Hacking - Part 3
SecurityFWD via YouTube
Running Away from Security - Web App Vulnerabilities and OSINT Collide
YouTube
IoT Goes Nuclear - Creating a Zigbee Chain Reaction
IEEE via YouTube