Back Issues/Search Home → Calendar → Archive → RSS → Subscribe → Current Issue → Popular →

All issues › Volume 342, Issue 4 › IT Vendor News › Google

Proactive Defense: Hardening Code Pipelines and CI/CD Infrastructure

Google, Thursday, September 24th, 2026

Google's threat intel team warns attackers increasingly compromise trusted CI/CD tools, IDEs, and pipeline credentials to attack builds.

Google's threat intelligence team describes a shift in software supply chain attacks, with sophisticated actors compromising trusted security scanners, utility libraries, and AI developer tools to exploit the elevated privileges those tools hold in build pipelines.

Adversaries also target developer workstations and IDEs through social engineering, malicious extensions, and typosquatted dependencies to steal cryptographic keys, API tokens, and session credentials.

Beyond stealing static credentials, attackers use advanced pipeline manipulation such as GitHub Actions cache poisoning, OIDC token extraction, and subverting mutable action tags to publish malicious code. The post recommends hardening measures to defend CI/CD infrastructure against these techniques.

more →  ·  More from Google →