Iβm a cybersecurity pro with a knack for breaking (and fixing) things. I spent a decade as a developer at startups and big companies before jumping into security research. Now, Iβm a Principal Researcher at Palo Alto Networks, specializing in AppSec and LLM security.
Side note: when Iβm not poking holes in code, Iβm a certified master diver π€Ώ and make a mean ramen noodle soup π. Seriously, itβs legendary.
Analysis of how GitHub repository artifacts can inadvertently leak sensitive tokens and credentials, exposing organizations to security risks.
Read More βIn-depth research on supply chain vulnerabilities in GitHub Actions workflows and how attackers can exploit CI/CD pipelines.
Read More βInvestigation into GitHub Actions that cannot be pinned to specific versions, creating potential security vulnerabilities.
Read More βAnalysis of GitHub Actions permission models and the security implications of opt-out vs opt-in approaches.
Read More βBest practices and recommendations for securing GitHub organizations through proper Identity and Access Management.
Read More βGeekTime coverage (Hebrew) of the ArtiPACKED vulnerability research, highlighting how this attack vector affects major companies like Canonical, Google, AWS, and Microsoft.
Read Article βA deliberately vulnerable CI/CD environment designed for learning and testing security vulnerabilities in CI/CD pipelines. This hands-on educational platform helps security professionals understand and practice identifying CI/CD security issues.
View on GitHub βActions have consequences: The overlooked Security Risks in 3rd party GitHub Actions
Watch on YouTube βRaiders of the Lost Artifacts: Racing for Hidden Treasures in Public GitHub Repositories
Watch on YouTube βThink Before You Prompt: Securing Large Language Models from a Code Perspective
More Info βInterested in collaborating on cybersecurity research or discussing CI/CD security?