
Team PCP、2,186組織から78,330件のsecretを窃取
CloudSEKのTeam PCP datasetは、侵害open-source componentが信頼されたpipelineで動いた後、5日間で2,186組織から78,330件のsecretが流出したと記録します。GitLab、Azure DevOps、GitHub、host、mail system全体でJWT 999組織、private key 480組織、AWS key 320組織、OpenAI key 157組織が含まれます。攻撃者は盗んだrepository・publishing credentialで次のsupply-chain compromiseを生むflywheelを作ります。StepSecurityは即時rotation後のdownstream access audit、immutable dependency reference、runner runtime monitoring、deny-by-default egressを勧めます。Vendor分析という制約はありますが、公開規模とcredential classはpipeline boundaryを無視できなくします。

