Post #3278507
2026-05-23 09:15 UTC
But as we secure the front door, the threat displaces. At NDSS 2026, Prof. William Enck showed how attackers are now targeting the CI/CD pipelines themselves, using cache blasting and Pwn Requests to hijack the automated assembly line. Watch here: https://youtu.be/rifS4khiNoM 3/5
Replies (1)
-
@joebeone@techpolicy.social 2026-05-23 09:15
Even if our pipelines are secure, our vulnerability data is a mess. Human maintainers cannot manually write VEX statements (attestations that a flagged bug is actually unreachable) for every false positive. We need automated verification like directed greybox fuzzing. 4/5