writeups.xyz writeups.xyz / Adnan Khan (@Adnanthekhan)

Title Vulnerabilities Programs Authors
RoguePuppet – A Critical Puppet Forge Supply Chain Vulnerability
The Monsters in Your Build Cache – GitHub Actions Cache Poisoning
An Obscure Actions Workflow Vulnerability in Google’s Flank
Fixing Typos And Breaching Microsoft’s Perimeter
Web3’s Achilles’ Heel: A Supply Chain Attack on Astar Network
TensorFlow Supply Chain Compromise via Self-Hosted Runner Attack
Playing With Fire – How We Executed A Critical Supply Chain Attack On Pytorch
One Supply Chain Attack to Rule Them All
Long Live the Pwn Request: Hacking Microsoft GitHub Repositories and More
Back to the 90s: Fujitsu “IP series” Real-time Video Transmission Gear Hard Coded Credentials
From Self-Hosted GitHub Runner to Self-Hosted Backdoor