Security researchers from Strix AI demonstrated how they gained admin-level access to Baseten's production GitHub organization within 25 minutes by exploiting a leaked Harbor CI/CD personal access token. The incident highlights critical supply chain and secrets management vulnerabilities in CI/CD pipelines.
Background
Baseten is an MLOps platform for deploying and serving machine learning models. Harbor is a container registry that also provides CI/CD integration, making it a common target for supply chain attacks.
- Source
- Hacker News (RSS)
- Published
- Sep 16, 2026 at 02:11 AM
- Score
- 8.0 / 10