
Your CI/CD Pipeline is My Attack Path: Graphing GitHub OIDC to Cloud Takeover | SO-CON 2026
Source: YouTube · SpecterOps · published Jun 4, 2026 · 50:00
[BLUF] This video analyzes identity federation vulnerabilities in CI/CD pipelines, specifically focusing on GitHub Actions' OIDC authentication with AWS, and reviews recent breaches to demonstrate prevention strategies using BloodHound 0:00.
Key Takeaways:
• The presenter introduces the "identity federation problem," explaining how it creates complex attack paths across cloud environments that organizations must understand to secure their infrastructure 0:09.
• A deep dive into how GitHub Actions authenticates to AWS via OpenID Connect (OIDC) is provided, highlighting the mechanisms and potential misconfigurations inherent in this setup 0:17.
• Two relevant case studies of recent breaches are examined to illustrate the real-world impact of these vulnerabilities, including an incident from 2025 and one with ongoing effects as of April 0:22.
• The session concludes with methods to identify and prevent cross-cloud attack paths before they occur, utilizing BloodHound for visualization and analysis of these complex relationships 0:36.
Understanding the intricacies of identity federation is crucial for mitigating risks in modern CI/CD workflows. By leveraging tools like BloodHound, teams can proactively secure their cloud environments against emerging threats.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 1 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
All right. Hey guys. So this is your CI/CD pipeline is by Attack Path. So today we're going to talk about a few things. The first thing we're going to talk about is the identity federation problem. What is identity federation? Why do we care about it and how does it affect my organization? Then we're going to get into how GitHub actions authenticates to AWS in depth through OIDC. We're going to talk about two case studies. And so these are two breaches that are recent and relevant. The first happened in 2025. And the second we're actually still dealing with the effects today. The last update was on April 1st. And then finally we're going to talk about how we can identify and prevent these cross-cloud attack paths before they happen [snorts] with BloodHound. So a little bit about me. My nam…