CI/CD GitHub Actions

Dragged Anchor

A GitHub Actions workflow contains sensitive information that needs to be extracted and shared externally

Exposure Azure

Phantom Fish

A Public Azure Storage Account exposes more than just the visible blob contents

K8S AWS

Leaky Fishing Net

A vulnerable web application provides access to Kubernetes cluster resources that shouldn't be exposed

CIEM GCP

Into the Undertow

GCP service accounts have interconnected permissions that can be leveraged to access protected secrets