logo

Public Travis CI Logs (Still) Expose Users to Cyber Attacks

ID: 219a78b9-f711-5663-9993-ff207de517f5

STIX ID: report--219a78b9-f711-5663-9993-ff207de517f5

Feed Name: Aqua Security Blog

Threat Score
78/100

Date Published: 2022-06-13

Date Updated: 2026-04-26

...
...

Team Nautilus discovered that Travis CI APIs allow unauthenticated enumeration and retrieval of historical build logs (estimated range ~4.28M–774.8M, roughly 770 million logs), leading to the exposure of tens of thousands of secrets (GitHub OAuth tokens, AWS keys, Docker Hub credentials). Their research documents enumeration methods, sampling results (~73,000 extracted tokens/secrets), simulated attack scenarios showing lateral movement, supply-chain and data-exfiltration risks, and recommends immediate mitigations such as key rotation, secrets scanning, least-privilege controls, and improved CI logging practices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.