Adnan Khan's Security Research Blog
Security research focused on CI/CD vulnerabilities, software supply chain attacks, and developer tooling security.
Latest posts
Clinejection — Compromising Cline's Production Releases just by Prompting an Issue Triager
Copilot or Coconspirator - Tricking GitHub Copilot and Stealing all Your Secrets
Who's SHA is it Anyway: Bypassing Google Cloud Build Comment Control for $30,000
Watch your Dispatch: Race Condition in Dependabot Core CI
(Not So) Safe{Wallet}: GitHub Actions Risks Impacting Safe''s Frontend
Cacheract: The Monster in your Build Cache
In this post, I demonstrate Cacheract, which is an open source proof-of-concept for 'Cache Native Malware' that exploits GitHub Actions cache misconfigurations.