From S3 bucket to Jenkins credential dump (Research)
ID: 0f984f8c-c519-5566-901f-7e32197a9222
STIX ID: report--0f984f8c-c519-5566-901f-7e32197a9222
Feed Name: Wiz Cloud Threat Landscape
Date Published: 2022-01-13
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
NCC Group’s pentest uncovered an exposed S3 bucket with directory listing that contained a script embedding a hardcoded Git credential; this allowed researchers to access a Jenkins instance, escalate to admin, and extract sensitive credentials (AWS tokens, SSH certificates), illustrating how cloud misconfigurations and embedded secrets can lead to CI/CD compromise and credential theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
