GitHub Supply Chain Security CI/CD Vulnerabilities Developer Infrastructure TeamPCP Software Integrity Threat Intelligence

The Trust Layer Is the Target

In six weeks, adversaries executed a systematic campaign against GitHub's core infrastructure — RCE exploits, poisoned VS Code extensions, Actions token theft, and 3,800 internal repos exfiltrated. The real threat is what happens when the layer that vouches for software integrity is compromised.

Episode

00:00:00 00:00:00