
Crypto group ushers in post-quantum security
Here’s a look at the Ethereum Foundation’s new PQC security effort — and why you need to modernize your SecOps.
CI/CD tampering refers to the unauthorized manipulation or exploitation of continuous integration (CI) or continuous delivery/deployment (CD) environments to inject malicious code, exfiltrate sensitive information, or alter build outcomes. It targets automated software pipelines that orchestrate testing, packaging, and release.
CI/CD environments often have access to sensitive credentials, source code, and deployment infrastructure. If compromised, they provide attackers with a powerful vector for software supply chain attacks, enabling the insertion of backdoors, lateral movement, or privilege escalation within the development workflow.
Tampering can occur at any stage of the pipeline and typically includes:
Topic | Focus Area | Key Differences |
|---|---|---|
Build Pipeline Security | Holistic protection of CI/CD tools | CI/CD tampering is a specific type of threat to that pipeline |
Artifact Poisoning | Tampered output artifacts | CI/CD tampering can lead to artifact poisoning |
Secure Build Environments | Infrastructure hardening | Focuses on securing the infrastructure, not the workflow logic |

Here’s a look at the Ethereum Foundation’s new PQC security effort — and why you need to modernize your SecOps.

AI agents create novel attack surfaces and control issues that require rethinking assumptions — and AppSec tooling.

Here's how to assess a sample using Spectra Analyze in your environment — and create a YARA rule.