Hell’s Keychain: Supply-chain vulnerability in IBM Cloud Databases for PostgreSQL allows potential unauthorized database access
ID: d16a3696-cc33-5946-9541-a2d7b8940dd6
STIX ID: report--d16a3696-cc33-5946-9541-a2d7b8940dd6
Feed Name: Wiz Blog
Threat Score
**Executive summary:** Wiz Research discovered "Hell’s Keychain," a supply-chain vulnerability in IBM Cloud Databases for PostgreSQL that combined three exposed secrets (a Kubernetes service account token, container registry credentials, and CI/CD server credentials) with overly permissive network access to internal build servers, enabling authentication to internal infrastructure and potential modification of build artifacts; IBM Cloud was notified and patched the issues.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
