CyberWire Daily

Foreign routers get a longer lifeline.

May 11, 2026
Dan Lorenc, CEO and co-founder of Chainguard and software supply chain expert, discusses a wave of AI-assisted supply chain attacks. He explains how CI/CD systems are being targeted and why build pipelines are high-value. He outlines mitigations like treating build systems as production and warns that AI is scaling attacker operations.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

CI/CD Became The New High‑Value Attack Surface

  • Supply chain attacks now target CI/CD as the highest‑value vector into production systems.
  • Dan Lorenc described attackers exploiting CI/CD test runners to steal publishing keys and inject malware into widely used packages like Trivy and Axios.
ANECDOTE

Security Scanner Got Backdoored And Stole Credentials

  • Attackers reused stolen keys to inject malware into a security scanner so the scanner stole credentials from every project it ran in.
  • Dan Lorenc recounted Trivy being backdoored for hours, enabling mass credential theft before removal.
INSIGHT

Insecure Defaults Make CI/CD Fragile

  • CI/CD ecosystems are fragile because many defaults and primitives are insecure by design.
  • Lorenc pointed out GitHub Actions' design choices require many manual steps to reach secure configurations at scale.
Get the Snipd Podcast app to discover more snips from this episode
Get the app