logo

Hell’s Keychain: Supply-chain vulnerability in IBM Cloud Databases for PostgreSQL allows potential unauthorized database access

ID: d16a3696-cc33-5946-9541-a2d7b8940dd6

STIX ID: report--d16a3696-cc33-5946-9541-a2d7b8940dd6

Feed Name: Wiz Blog

Threat Score
85/100

Date Published: 2022-12-01

Date Updated: 2026-05-01

...
...

**Executive summary:** Wiz Research discovered "Hell’s Keychain," a supply-chain vulnerability in IBM Cloud Databases for PostgreSQL that combined three exposed secrets (a Kubernetes service account token, container registry credentials, and CI/CD server credentials) with overly permissive network access to internal build servers, enabling authentication to internal infrastructure and potential modification of build artifacts; IBM Cloud was notified and patched the issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.