THREATOPS
THREAT OPSThreat News › CI/CD pipeline abuse: the problem no one is watching

CI/CD pipeline abuse: the problem no one is watching

lowelastic_securityPublished 2026-04-29

<h2 id="preamble">Preamble</h2> <p>In 2025 and 2026, we watched a pattern play out across the industry. Attackers stopped going after production servers directly and started targeting the automation that deploys to them. Compromised developer credentials, a modified workflow file, and suddenly every secret in a CI/CD environment is streaming to an attacker-controlled endpoint. We saw this play out

Attributed threat actors

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.elastic.co/security-labs/threat-command/detecting-cicd-pipeline-abuse-with-llm-augmented-analysis