Jan. 18, 2024, 12:34 p.m. | info@thehackernews.com (The Hacker News)

The Hacker News thehackernews.com

Continuous integration and continuous delivery (CI/CD) misconfigurations discovered in the open-source TensorFlow machine learning framework could have been exploited to orchestrate supply chain attacks.
The misconfigurations could be abused by an attacker to "conduct a supply chain compromise of TensorFlow releases on GitHub and PyPi by compromising TensorFlow's build agents via

attacker attacks build compromise continuous continuous delivery continuous integration delivery exploited exposed flaw framework github integration machine machine learning misconfigurations poisoning poisoning attacks pypi releases supply supply chain supply chain attacks supply chain compromise tensorflow

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC