Your CI/CD Pipeline is My Attack Path: Graphing GitHub OIDC to Cloud Takeover | SO-CON 2026

Your CI/CD Pipeline is My Attack Path: Graphing GitHub OIDC to Cloud Takeover | SO-CON 2026

Source: YouTube · SpecterOps · published Jun 4, 2026 · 50:00

Cloud Security
No ratings yet Log in to rate
Transcript Available
Description

[BLUF] This video analyzes identity federation vulnerabilities in CI/CD pipelines, specifically focusing on GitHub Actions' OIDC authentication with AWS, and reviews recent breaches to demonstrate prevention strategies using BloodHound 0:00.

Key Takeaways:
• The presenter introduces the "identity federation problem," explaining how it creates complex attack paths across cloud environments that organizations must understand to secure their infrastructure 0:09.
• A deep dive into how GitHub Actions authenticates to AWS via OpenID Connect (OIDC) is provided, highlighting the mechanisms and potential misconfigurations inherent in this setup 0:17.
• Two relevant case studies of recent breaches are examined to illustrate the real-world impact of these vulnerabilities, including an incident from 2025 and one with ongoing effects as of April 0:22.
• The session concludes with methods to identify and prevent cross-cloud attack paths before they occur, utilizing BloodHound for visualization and analysis of these complex relationships 0:36.

Understanding the intricacies of identity federation is crucial for mitigating risks in modern CI/CD workflows. By leveraging tools like BloodHound, teams can proactively secure their cloud environments against emerging threats.

Sources:

  • 0:00 Introduction to CI/CD pipeline security and attack paths
  • 0:09 Definition and importance of the identity federation problem
  • 0:17 In-depth explanation of GitHub Actions OIDC authentication to AWS
  • 0:22 Discussion of two recent breach case studies
  • 0:36(https://www.

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cloud Security. Commonly maps to: Security Architecture and Engineering, Communication and Network Security. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

All right. Hey guys. So this is your CI/CD pipeline is by Attack Path. So today we're going to talk about a few things. The first thing we're going to talk about is the identity federation problem. What is identity federation? Why do we care about it and how does it affect my organization? Then we're going to get into how GitHub actions authenticates to AWS in depth through OIDC. We're going to talk about two case studies. And so these are two breaches that are recent and relevant. The first happened in 2025. And the second we're actually still dealing with the effects today. The last update was on April 1st. And then finally we're going to talk about how we can identify and prevent these cross-cloud attack paths before they happen [snorts] with BloodHound. So a little bit about me. My nam…