Aqua News Supply Chain Attacks and Cloud Native: What You Need to Know

Container images, functions and packages are updated frequently using CI/CD (continuous integration/continuous delivery) pipelines, creating multiple opportunities for attackers to embed themselves into the process. Team Nautilus, Aqua’s cyber research team, has detected and analyzed attacks on CI SaaS environments that abused the CI process itself to gain access to cloud CPU time. From there, it’s a relatively short hop into the artifacts being built in those CI pipelines.

Read more ›