Yaron Avital

I’m a cybersecurity pro with a knack for breaking (and fixing) things. I spent a decade as a developer at startups and big companies before jumping into security research. Now, I’m a Principal Researcher at Palo Alto Networks, specializing in AppSec and LLM security.

Side note: when I’m not poking holes in code, I’m a certified master diver 🀿 and make a mean ramen noodle soup 🍜. Seriously, it’s legendary.

GitHub Security CI/CD Security Supply Chain Attacks DevSecOps

Research Publications

ArtiPACKED

GitHub Repository Artifacts Leak Tokens

Analysis of how GitHub repository artifacts can inadvertently leak sensitive tokens and credentials, exposing organizations to security risks.

Read More β†’
tj-actions GitHub Action Supply Chain Attack

tj-actions GitHub Action Supply Chain Attack

In-depth research on supply chain vulnerabilities in GitHub Actions workflows and how attackers can exploit CI/CD pipelines.

Read More β†’
Unpinnable Actions

Unpinnable Actions GitHub Security

Investigation into GitHub Actions that cannot be pinned to specific versions, creating potential security vulnerabilities.

Read More β†’
Opt-Out Permissions Model

GitHub Actions Opt-Out Permissions Model

Analysis of GitHub Actions permission models and the security implications of opt-out vs opt-in approaches.

Read More β†’
Prevent Inadequate IAM GitHub Organization

Prevent Inadequate IAM GitHub Organization

Best practices and recommendations for securing GitHub organizations through proper Identity and Access Management.

Read More β†’
GeekTime ArtiPACKED Coverage

A New Security Breach in GitHub Actions Threatens Software Giants

GeekTime coverage (Hebrew) of the ArtiPACKED vulnerability research, highlighting how this attack vector affects major companies like Canonical, Google, AWS, and Microsoft.

Read Article β†’

Open Source Projects

Prevent Inadequate IAM GitHub Organization

CICD Goat

A deliberately vulnerable CI/CD environment designed for learning and testing security vulnerabilities in CI/CD pipelines. This hands-on educational platform helps security professionals understand and practice identifying CI/CD security issues.

View on GitHub β†’

Conference Talks

BSidesLV 2023

Actions have consequences: The overlooked Security Risks in 3rd party GitHub Actions

Watch on YouTube β†’

BSidesLV 2024

Raiders of the Lost Artifacts: Racing for Hidden Treasures in Public GitHub Repositories

Watch on YouTube β†’
OWASP Logo
Global AppSec Barcelona 2025
Think Before You Prompt
Securing LLMs from a Code Perspective

OWASP Global AppSec Barcelona 2025

Think Before You Prompt: Securing Large Language Models from a Code Perspective

More Info β†’

Let's Connect

Interested in collaborating on cybersecurity research or discussing CI/CD security?