AWS GitHub repos were hijacked via Codebuild in a supply chain vulnerability that abused a CI/CD misconfiguration.
CodeBreach was thankfully discovered by Wiz researchers first, but security Misconfigurations are the number 2 risk in the OWASP Top 10 and especially easy to look over when there are so many small tweaks to configuring how you build and deploy an app end-to-end.
——
Follow
@cyberjasbytes for more cybersecurity news
——
#aws #supplychain #cybersecurity #technews #engineer
🏷️: aws codebuild, aws hack, wiz security, aws code breach, supply chain vulnerabilities, owasp top 10, cloud security, infrastructure security, sdlc, ci/cd pipelines, developers, coding, github