top of page
The CI/CD Pipeline Is the Attack Surface
Adding a SAST scanner to your CI/CD pipeline is not the same as securing it. Three documented incidents from the past 13 months — tj-actions, Trivy, and Axios — show how the pipeline execution layer, dependency installation, and runner credentials are all being targeted at scale. Episode 9 builds the threat model your shift-left programme is missing.
Christopher Clarkson
Apr 712 min read
Vulnerability Management at Scale: When 60,000 CVEs Per Year Breaks Your Triage Model
FIRST is projecting a median of 59,427 CVEs for 2026. At that volume, a process that requires a human to review each inbound finding is not a triage model — it is a queue that will never clear. Episode 8 covers vulnerability management at scale: the composite scoring model that handles automated classification, why KEV is a hard floor and not a scoring input, and where the asset inventory is still the bottleneck.
Christopher Clarkson
Mar 319 min read
bottom of page
