<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Adnan Khan&apos;s Security Research Blog</title><description>Security research focused on CI/CD vulnerabilities, software supply chain attacks, and developer tooling security.</description><link>https://adnanthekhan.com/</link><language>en-us</language><item><title>Turning Almost Nothing into a Supply Chain Compromise of Angular with GitHub Actions Cache Poisoning</title><link>https://adnanthekhan.com/posts/angular-compromise-through-dev-infra/</link><guid isPermaLink="true">https://adnanthekhan.com/posts/angular-compromise-through-dev-infra/</guid><pubDate>Tue, 03 Mar 2026 00:00:00 GMT</pubDate><category>cache-poisoning</category><category>githubactions</category><category>bugbounty</category><author>adnanthekhan</author></item><item><title>Clinejection — Compromising Cline&apos;s Production Releases just by Prompting an Issue Triager</title><link>https://adnanthekhan.com/posts/clinejection/</link><guid isPermaLink="true">https://adnanthekhan.com/posts/clinejection/</guid><pubDate>Mon, 09 Feb 2026 09:00:00 GMT</pubDate><category>cicd</category><category>githubactions</category><category>cache-poisoning</category><category>ai</category><author>adnanthekhan</author></item><item><title>Copilot or Coconspirator - Tricking GitHub Copilot and Stealing all Your Secrets</title><link>https://adnanthekhan.com/posts/copilot-or-co-conspirator/</link><guid isPermaLink="true">https://adnanthekhan.com/posts/copilot-or-co-conspirator/</guid><pubDate>Wed, 07 Jan 2026 00:00:00 GMT</pubDate><category>cicd</category><category>ai</category><category>github</category><category>bugbounty</category><author>adnanthekhan</author></item><item><title>Who&apos;s SHA is it Anyway: Bypassing Google Cloud Build Comment Control for $30,000</title><link>https://adnanthekhan.com/posts/cloud-build-toctou/</link><guid isPermaLink="true">https://adnanthekhan.com/posts/cloud-build-toctou/</guid><pubDate>Mon, 21 Jul 2025 10:00:00 GMT</pubDate><category>cicd</category><category>bugbounty</category><author>adnanthekhan</author></item><item><title>Watch your Dispatch: Race Condition in Dependabot Core CI</title><link>https://adnanthekhan.com/posts/dependabot-core-toctou-writeup/</link><guid isPermaLink="true">https://adnanthekhan.com/posts/dependabot-core-toctou-writeup/</guid><pubDate>Fri, 02 May 2025 18:00:00 GMT</pubDate><category>bugbounty</category><category>cicd</category><category>github</category><author>adnanthekhan</author></item><item><title>(Not So) Safe{Wallet}: GitHub Actions Risks Impacting Safe&apos;&apos;s Frontend</title><link>https://adnanthekhan.com/2025/02/27/not-so-safewallet-github-actions-risks-impacting-safes-frontend/</link><guid isPermaLink="true">https://adnanthekhan.com/2025/02/27/not-so-safewallet-github-actions-risks-impacting-safes-frontend/</guid><pubDate>Thu, 27 Feb 2025 23:59:48 GMT</pubDate><category>cicd</category><category>githubactions</category><category>security</category><category>supplychain</category><category>github</category><category>web3</category><author>adnanthekhan</author></item><item><title>Cacheract: The Monster in your Build Cache</title><link>https://adnanthekhan.com/2024/12/21/cacheract-the-monster-in-your-build-cache/</link><guid isPermaLink="true">https://adnanthekhan.com/2024/12/21/cacheract-the-monster-in-your-build-cache/</guid><description>In this post, I demonstrate Cacheract, which is an open source proof-of-concept for &apos;Cache Native Malware&apos; that exploits GitHub Actions cache misconfigurations.</description><pubDate>Sun, 22 Dec 2024 00:02:52 GMT</pubDate><category>cicd</category><category>githubactions</category><category>security</category><category>supplychain</category><author>adnanthekhan</author></item><item><title>Release-Drafter To google/accompanist Compromise: VRP Writeup</title><link>https://adnanthekhan.com/2024/11/11/release-drafter-to-google-accompanist-compromise-vrp-writeup/</link><guid isPermaLink="true">https://adnanthekhan.com/2024/11/11/release-drafter-to-google-accompanist-compromise-vrp-writeup/</guid><pubDate>Tue, 12 Nov 2024 02:35:40 GMT</pubDate><category>bugbounty</category><category>cicd</category><category>githubactions</category><category>security</category><category>github</category><author>adnanthekhan</author></item><item><title>BlackHat 2024 and DEF CON 32 Preview</title><link>https://adnanthekhan.com/2024/07/30/blackhat-2024-and-def-con-32-preview/</link><guid isPermaLink="true">https://adnanthekhan.com/2024/07/30/blackhat-2024-and-def-con-32-preview/</guid><pubDate>Tue, 30 Jul 2024 13:00:00 GMT</pubDate><category>bugbounty</category><category>github</category><category>githubactions</category><category>security</category><category>devops</category><category>github-actions</category><author>adnanthekhan</author></item><item><title>RoguePuppet - A Critical Puppet Forge Supply Chain Vulnerability</title><link>https://adnanthekhan.com/2024/07/02/roguepuppet-a-critical-puppet-forge-supply-chain-vulnerability/</link><guid isPermaLink="true">https://adnanthekhan.com/2024/07/02/roguepuppet-a-critical-puppet-forge-supply-chain-vulnerability/</guid><pubDate>Tue, 02 Jul 2024 09:57:09 GMT</pubDate><category>cicd</category><category>githubactions</category><category>security</category><category>supplychain</category><category>github</category><category>github-actions</category><author>adnanthekhan</author></item><item><title>The Monsters in Your Build Cache - GitHub Actions Cache Poisoning</title><link>https://adnanthekhan.com/2024/05/06/the-monsters-in-your-build-cache-github-actions-cache-poisoning/</link><guid isPermaLink="true">https://adnanthekhan.com/2024/05/06/the-monsters-in-your-build-cache-github-actions-cache-poisoning/</guid><pubDate>Mon, 06 May 2024 09:41:00 GMT</pubDate><category>bugbounty</category><category>cicd</category><category>github</category><category>supplychain</category><category>devops</category><category>github-actions</category><author>adnanthekhan</author></item><item><title>An Obscure Actions Workflow Vulnerability in Google&apos;s Flank</title><link>https://adnanthekhan.com/2024/04/15/an-obscure-actions-workflow-vulnerability-in-googles-flank/</link><guid isPermaLink="true">https://adnanthekhan.com/2024/04/15/an-obscure-actions-workflow-vulnerability-in-googles-flank/</guid><pubDate>Mon, 15 Apr 2024 14:00:00 GMT</pubDate><category>bugbounty</category><category>cicd</category><category>github</category><category>security</category><category>supplychain</category><author>adnanthekhan</author></item><item><title>Web3&apos;&apos;s Achilles&apos;&apos; Heel: A Supply Chain Attack on Astar Network</title><link>https://adnanthekhan.com/2024/01/19/web3s-achilles-heel-a-supply-chain-attack-on-astar-network/</link><guid isPermaLink="true">https://adnanthekhan.com/2024/01/19/web3s-achilles-heel-a-supply-chain-attack-on-astar-network/</guid><pubDate>Fri, 19 Jan 2024 22:09:11 GMT</pubDate><category>bugbounty</category><category>cicd</category><category>github</category><category>security</category><category>supplychain</category><category>astar</category><category>crypto</category><category>defi</category><category>web3</category><author>adnanthekhan</author></item><item><title>CVE-2023-49291 and More - A Potential Actions Nightmare</title><link>https://adnanthekhan.com/2024/01/10/cve-2023-49291-and-more-a-potential-actions-nightmare/</link><guid isPermaLink="true">https://adnanthekhan.com/2024/01/10/cve-2023-49291-and-more-a-potential-actions-nightmare/</guid><pubDate>Thu, 11 Jan 2024 02:37:44 GMT</pubDate><category>cicd</category><category>github</category><category>security</category><category>supplychain</category><category>cve</category><author>adnanthekhan</author></item><item><title>One Supply Chain Attack to Rule Them All - Poisoning GitHub&apos;s Runner Images</title><link>https://adnanthekhan.com/2023/12/20/one-supply-chain-attack-to-rule-them-all/</link><guid isPermaLink="true">https://adnanthekhan.com/2023/12/20/one-supply-chain-attack-to-rule-them-all/</guid><pubDate>Wed, 20 Dec 2023 20:37:53 GMT</pubDate><category>bugbounty</category><category>cicd</category><category>github</category><category>security</category><category>supplychain</category><author>adnanthekhan</author></item><item><title>Welcome to my blog - there is more to come!</title><link>https://adnanthekhan.com/2023/12/16/welcome-to-my-blog-there-is-more-to-come/</link><guid isPermaLink="true">https://adnanthekhan.com/2023/12/16/welcome-to-my-blog-there-is-more-to-come/</guid><pubDate>Sat, 16 Dec 2023 18:05:08 GMT</pubDate><category>bugbounty</category><category>cicd</category><category>security</category><author>adnanthekhan</author></item></channel></rss>