DevOps Bulletin

DevOps Bulletin

Digest #205: GitHub Actions Exploitation, Terraform Internals, Passkeys Warning and Go Runtime

A bot exploiting GitHub Actions across Microsoft and CNCF projects, Terraform internals deep-dive, npm token theft via CI, and Go runtime scheduler explained.

Mohamed Labouardy's avatar
Mohamed Labouardy
Mar 13, 2026
∙ Paid

Welcome to this week’s edition of the DevOps Bulletin.

An autonomous bot spent 7 days exploiting GitHub Actions across Microsoft, DataDog, Aqua Security, and CNCF projects — exfiltrating tokens with w…

User's avatar

Continue reading this post for free, courtesy of Mohamed Labouardy.

Or purchase a paid subscription.
© 2026 Mohamed Labouardy · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture