buildOne report1 publisher A HackerOne report says DuckDuckGo's semver-label.yml ran code from any forked pull request with secrets in its environment. Any team can search its own workflows for pull_request_target to find the same pattern.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+35
- Incentives
- Insufficient
- Confidence50
buildOne report1 publisher Rust's nightly of 22 September 2026 stops Miri copying environment variables into the target/ directories CI jobs cache. Caches saved earlier still hold any secret a Miri step saw, so teams have to delete them and rotate those credentials.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Unit 42 says supply-chain attackers have moved command-and-control into blockchain smart contracts, so one transaction can re-point an entire botnet or worm. Defenders' useful choke points are now developer machines, CI runners and the chain lookup itself.
Reality
- Evidence55
- Adoption45
- Hype gap+15
- Incentives45
- Confidence55
buildOne report1 publisher ZoomEye queries on 22 September 2026 found 1,538 Jenkins, 169 Harbor and 32 SonarQube instances reachable from the internet. These tools hold deploy credentials by design, so every reachable instance is a possible route into production.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
buildOne report1 publisher Bouras, Dai and Mechtaev found a static denylist let 46 of 75 prompt injections execute in a coding agent, against 3 under preflight-scoped capabilities. A same-day Google report of malware stealing OIDC tokens from GitHub Actions runners puts the outer limit on an agent in the CI job's permissions.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
GitLab's September 10 patch release closes CVE-2026-85706, a CVSS 10.0 path confinement failure in the repository commits API. GitLab.com was already patched, so the exposure sits with self-managed servers.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 62%
- Investor
- Investor 5%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+5
- Incentives30
- Confidence70
buildOne report1 publisher Go 1.27 ran none of a poisoned module's code on go get, go build or go vet in a replay of npm's August 4 worm, but go test ran it with GITHUB_TOKEN in reach. Go teams still carry exposure through CI test runs, versions that stay cached for good, and bots that edit go.mod.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Two actions-cool GitHub Actions hijacked on May 18 came back online on September 16, still serving the Mini Shai-Hulud stealer to tag-pinned workflows. Only workflows pinned to a pre-May 18 commit SHA escaped; the rest have CI secrets to rotate.
Perspective Coverage
3 publishers
- Builder
- Builder 43%
- Operator
- Operator 47%
- Investor
- Investor 10%
Reality
- Evidence60
- Adoption40
- Hype gap+15
- Incentives30
- Confidence65
buildOne report1 publisher Socket says workflows using issues-helper@v2.2.1 re-ran Mini Shai-Hulud after the Action was re-enabled on September 16 with its malicious tags intact. The earlier takedown only made those jobs fail, so the fix that holds is dropping the Action or pinning a verified commit SHA.
Reality
- Evidence55
- Adoption35
- Hype gap+10
- Incentives
- Insufficient
- Confidence55
buildOne report1 publisher Malware that steals a developer's Git credentials force-pushes a poisoned vite.config.js to every reachable branch, a dozen rewritten in a minute in one case. A routine git pull and build then runs it, and dependency scanners never see the change.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence50
Ransomnews says it found more than 50,000 exposed Stripe merchant secret keys and tested a sample. One live key to a customer list and a test charge took 17 hours.
Reality
- Evidence40
- Adoption
- Insufficient
- Hype gap+30
- Incentives
- Insufficient
- Confidence42
Unit 42 worked a ransomware intrusion where the operator handed tactical execution to frontier AI agents, and the chain from a public API endpoint to stolen cloud AI keys closed inside a single working day with no zero-day.
Reality
- Evidence50
- Adoption20
- Hype gap+25
- Incentives60
- Confidence55
buildOne report1 publisher Mandiant's findings say the intrusion never reached Checkmarx One or production AWS, and that answers the vendor's question rather than the one a customer has about what a build box pulled in late March.
Publishers:checkmarx.com
Reality
- Evidence38
- Adoption
- Insufficient
- Hype gap+25
- Incentives65
- Confidence45
buildConfirmed3 publishers The fix ships in 19.3.2, 19.2.6 and 19.1.8, and scanning for the flaw started the day after disclosure. Whether you can tell if a read succeeded on your instance depends on whether your proxy logs request bodies.
Publishers:dev.to · docs.gitlab.com · watchtowr.com Perspective Coverage
3 publishers
- Builder
- Builder 22%
- Operator
- Operator 73%
- Investor
- Investor 5%
Reality
- Evidence80
- Adoption
- Insufficient
- Hype gap+15
- Incentives45
- Confidence74
CISA said Sept. 23 that ransomware crews are exploiting CVE-2026-63077, an unauthenticated 9.8 RCE in JetBrains TeamCity patched July 25. Any build server patched late has to be handled as breached, including the credentials and signing keys it held.
Reality
- Evidence70
- Adoption75
- Hype gap+15
- Incentives35
- Confidence72
Three versions of MemTensor's MemOS Cloud plugin on npm and MemoryOS 2.0.34 on PyPI launch a Go stealer called sckit that reads the host environment and the user's prompt text, and the npm versions are still installable.
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence64
buildOne report1 publisher The canonical script-injection fix takes the untrusted expression out of run: and puts it in env:, and shape-matching scanners stop reading there. A new tool follows the value on into the composite action and the Node bundle that finally calls spawn().
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap−12
- Incentives60
- Confidence55
buildOne report1 publisher The fix for CVE-2026-85706 shipped on 10 September in 19.3.2, 19.2.6 and 19.1.8, and CISA listed the flaw as exploited the next day. A ZoomEye fingerprint count of 1,262,273 hosts does not report versions; it shows where to look.
Reality
- Evidence62
- Adoption38
- Hype gap+15
- Incentives78
- Confidence55
buildOne report1 publisher In a dev.to write-up, Jorge RN traces the chain from a workload's own identity to an ephemeral OCI session token, where the authorization decision reads claims such as repository, workflow and branch.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+25
- Incentives40
- Confidence35
buildOne report1 publisher All seven end in arbitrary code execution on the controller and all are fixed in one Script Security release, so the work is finding out which version of it each of your controllers actually runs.
Reality
- Evidence45
- Adoption30
- Hype gap−5
- Incentives30
- Confidence50
Earlier coverage
- Branch protection stopped the Terraform edits in Unit 42's ten-hour agent intrusion
Build · September 16, 2026 · One report1 publisher
- Malicious packages appeared every six minutes while defenders patched in days
Product · September 13, 2026 · One report1 publisher
- A CI leak drill measures the time between spotting a key in the log and revoking it
Build · September 11, 2026 · One report1 publisher
- A committed .github/copilot-instructions.md prepends a repository's invariants to every Copilot request
Build · September 11, 2026 · One report1 publisher
- JetBrains' final Cadence update moves the exposure from a 2024 backup into live storage
Security · September 7, 2026 · One report1 publisher
- A backdoored LiteLLM package cleared 119,000 downloads before PyPI quarantined it
Build · September 5, 2026 · One report1 publisher
- Unit 42 timed an agentic intrusion at fifty ATT&CK techniques in under ten hours
Science · September 5, 2026 · Confirmed2 publishers
- Unpatched TeamCity server gave attackers AWS IAM credentials from JetBrains' Cadence backup
Security · September 5, 2026 · One report1 publisher
- A missing attribute condition admits every identity its provider will vouch for
Build · August 31, 2026 · One report1 publisher
- Jenkins static AWS keys work from anywhere; the OIDC replacement fails in four known ways
Build · August 27, 2026 · One report1 publisher