Continuous Compromise: How Attackers are Targeting Cloud-Based CI/CD Pipelines and Deployments

No ratings

Presented at BSidesOttawa 2019 by

As DevOps continues to transform organizations and the use of cloud services becomes ubiquitous, it’s no surprise attackers (and pentesters!) are increasingly targeting the technologies that enable it. We’ll take a tour through a collection of real-life examples and case-studies to explore how vulnerabilities across the CI/CD stack and cloud service deployments are successfully targeted and exploited. Resulting in the disclosure of sensitive information, the co-opting of the build, deployment and orchestration infrastructure and potentially the compromise of the organization itself. But all is not lost, we will conclude with a number of recommendations for teams to raise their security bar without slowing velocity.