From code commit to production takeover (Research)
ID: ed504a5f-ce11-5bb0-a544-5c4d8d71a9f6
STIX ID: report--ed504a5f-ce11-5bb0-a544-5c4d8d71a9f6
Feed Name: Wiz Cloud Threat Landscape
Threat Score
Date Published: 2022-01-13
Date Updated: 2026-05-01
Author: [email protected] (Wiz Threat Research)
...
...
NCC Group pentest case study: by compromising a developer's build dependency to deliver a Meterpreter shell, researchers accessed a pod holding an SSH key for a Jenkins master and escalated to write privileges and cluster admin, enabling takeover of production. The report illustrates the high-risk impact of CI/CD and supply-chain compromises in modern build environments.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
