TWiET 525: Old Infrastructure Locked in the Closet - CircleCI security incident, API security, the state of service mesh
This Week in Enterprise Tech (Audio)
00:00
Cloud Platform Crypto Mining Campaign Using DevOps and CI CD Approaches
A threat group called automated Libra is keeping security pros up at night with their increasing use of modern software development techniques. Purple Urchin is using DevOps and continuous integration and continuous deployment or CI CD practices to mine cryptocurrency on cloud platforms Using free trial accounts. It's been going on since August 2019, and it's mainly targeted platforms like GitHub, Heroku and toggle box.
Play episode from 06:37
Transcript


