logo

10 real-world stories of how we’ve compromised CI/CD pipelines

ID: fc3090eb-1f1d-50f8-8545-8ca3b183fe31

STIX ID: report--fc3090eb-1f1d-50f8-8545-8ca3b183fe31

Feed Name: NCC Research

Threat Score
75/100

Date Published: 2025-09-23

Date Updated: 2026-08-03

...
...

NCC Group documents multiple CI/CD pipeline attack stories demonstrating how common misconfigurations and overly-permissive settings in Jenkins, GitLab, Kubernetes, and associated services (S3, Docker, AWS IAM) can lead to full environment compromise; each story outlines the attack path, impact (credential and secret exfiltration, host/container escapes, AWS/EKS admin access), and remediation recommendations to harden build pipelines and protect the software supply chain.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.