CuraSec

Plan active

Google TI Blueprint: Hardening CI/CD Pipelines Against Active Supply-Chain TTPs

2026-09-24 15:49 UTC · Google Threat Intelligence · read the source ↗ #ci-cd-security#supply-chain#github-actions
  • Engineer — Plan: Covers actively exploited vectors — OIDC token extraction, GitHub Actions cache poisoning, and mutable action tag hijacking — directly relevant to any team running modern pipelines; this quarter, pin all Action references to full commit SHAs, scope OIDC tokens to minimum claims per job, and audit build cache configurations for injection risk.
  • SOC/IR — Plan: The TTPs described (pipeline cache poisoning, OIDC token exfiltration, compromised scan tools executing in CI) map to credential-access and supply-chain-compromise ATT&CK techniques with a growing log surface; prioritize collecting GitHub Actions audit logs into SIEM and build detections for anomalous OIDC token issuance or unexpected cache write events.
  • Leader — Learn: Establishes that sophisticated actors are systematically targeting engineering toolchains — useful context for supply chain risk conversations with auditors or customers, but no specific vendor breach or regulatory deadline requiring immediate leadership action.
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.