logo

From code commit to production takeover (Research)

ID: ed504a5f-ce11-5bb0-a544-5c4d8d71a9f6

STIX ID: report--ed504a5f-ce11-5bb0-a544-5c4d8d71a9f6

Feed Name: Wiz Cloud Threat Landscape

Threat Score
75/100

Date Published: 2022-01-13

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

NCC Group pentest case study: by compromising a developer's build dependency to deliver a Meterpreter shell, researchers accessed a pod holding an SSH key for a Jenkins master and escalated to write privileges and cluster admin, enabling takeover of production. The report illustrates the high-risk impact of CI/CD and supply-chain compromises in modern build environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.