frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: SmokedMeat, like Metasploit, but for CI/CD (open-source)

https://github.com/boostsecurityio/smokedmeat
11•flexorium•1h ago
A CI/CD Red Team Framework for demonstrating Build Pipeline security risks.

Comments

flexorium•1h ago
OP here, mini AMA.

Two years ago today, our small research team open sourced poutine, a SAST scanner for CI/CD pipelines (very similar to zizmor, but written in Go and customizable using Rego DSL). It finds the vulnerabilities in your build pipelines. As all security engineers know, running SAST and filing a JIRA ticket leads to nowhere.

Some weeks ago TeamPCP came on the scene and most were shocked to see the blast radius starting with Trivy then LiteLLM, KICS, etc. Trivy got pwn'd using textbook "pwn request".

I've been building SmokedMeat for the past 5 months to level the playing field. It's a Red Team framework for CI/CD pipelines. You scan a GitHub org workflows, pick from a menu of exploitable pipelines, you are guided through an exploitation wizard, wait… and you're in post-exploitation. Secrets already exfiltrated from runner process memory are in the Loot stash, ready to pivot into cloud accounts, private repos, and more. Live attack graph in the browser.

To try it: git clone https://github.com/boostsecurityio/smokedmeat.git cd smokedmeat make quickstart

Then you target the whooli GitHub org (https://github.com/whooli) a CTF playground to exploit (hint the final flag is in a Google Cloud Storage Bucket)

Happy to answer questions about the ethics, architecture, implant design, or CI/CD attack techniques.

gepeto42•1h ago
The last year has shown that this vector is getting weaponized for real so it's great to see more tools to help defenders!

Is this something only companies with public repos should be worried about?

flexorium•1h ago
Absolutely not. The same TTPs apply almost 1-to-1 for Insider Threat scenarios. We've built the Deciduous Attack Trees (shout out to Kelly) for insider threats last year. It overlaps. So either you start with Initial Access that's purely public and pivot deeper or you already have a modest foothold (like intern with read only access) and off to the races.
bavarianbob•1h ago
I think this is a killer project that's very needed to accelerate the learning of how to defend against the deluge of nascent CI/CD risks. Kudos Boost team!
flexorium•1h ago
Thanks! I got tired of talking about it to defenders. I wanted to talk to Red Teamers too and SOC / detection engineering people. I wanted to build a tool that someone can just have the CISO try it directly.

BBC to cut up to 2k jobs in biggest downsize in 15 years

https://www.theguardian.com/media/2026/apr/15/bbc-cut-jobs-downsize-matt-brittin-tim-davie
1•mellosouls•1m ago•0 comments

Trump Killed the One Thing That Made Filing Taxes Easier

https://www.nytimes.com/2026/04/04/opinion/taxes-trump-direct-file-tax-day-april.html
2•mitchbob•2m ago•1 comments

Trust and the Death of the Handshake Deal

https://nickchirls.com/2026/04/15/trust-and-the-death-of-the-handshake-deal/
1•rafaelc•2m ago•0 comments

Close the Book. Recall. Write It Down. (2009)

https://www.chronicle.com/article/close-the-book-recall-write-it-down/
1•downbad_•3m ago•1 comments

Jensen Huang – How Nvidia locked up the semiconductor supply chain [video]

https://www.youtube.com/watch?v=Hrbq66XqtCo
1•tosh•4m ago•0 comments

Dino from Scratch

https://github.com/aldipiroli/dino_from_scratch
1•tgnk2341•4m ago•0 comments

Show HN: Tier – Adaptive tool routing that makes small LLMs 10pt more accurate

https://github.com/yantrikos/tier
2•pranabsarkar•5m ago•0 comments

Bot-AGI-1 – a robotics benchmark for VLMs

https://bot-agi.org/
1•chronolitus•5m ago•0 comments

Cram Less to Fit More: Training Data Pruning Improves Memorization of Facts

https://machinelearning.apple.com/research/cram-less
1•gmays•6m ago•0 comments

The Gemini app is now on Mac

https://blog.google/innovation-and-ai/products/gemini-app/gemini-app-now-on-mac-os/
1•thm•6m ago•0 comments

Python Type Checker Comparison: Speed and Memory Usage

https://pyrefly.org/blog/speed-and-memory-comparison/
1•ocamoss•6m ago•0 comments

Show HN: Agentfab – A Distributed Agentic Platform

https://github.com/RazvanMaftei9/agentfab
1•razvan_maftei•7m ago•0 comments

Patch Tuesday, April 2026 Edition

https://krebsonsecurity.com/2026/04/patch-tuesday-april-2026-edition/
1•Brajeshwar•7m ago•0 comments

New search engine reveals if ancestors were in Nazi party

https://www.bbc.com/news/articles/cr411ndee7yo
1•hackernj•8m ago•0 comments

Ecovacs Wants to Weaponize Your Mop Water

https://www.siliconsnark.com/ecovacs-wants-to-weaponize-your-mop-water/
1•SaaSasaurus•9m ago•0 comments

French cops free mother and son after 20-hour crypto kidnap ordeal

https://www.theregister.com/2026/04/15/crypto_kidnap_france/
1•Bender•9m ago•0 comments

Encrypted Client Hello: A Big Tech Privacy Fix

https://blog.miloslavhomer.cz/encrypted-client-hello/
1•ArcHound•11m ago•0 comments

Henry's Pocket

https://en.wikipedia.org/wiki/Henry%27s_pocket
1•thunderbong•12m ago•0 comments

Notes on Twins Vol. 2 – 12 Weeks

https://roryflint.substack.com/p/notes-on-twins-vol-2
2•mrroryflint•16m ago•1 comments

'Handing out the blueprint to a bank vault' Why AI led Cal to drop open source

https://www.zdnet.com/article/ai-security-worries-force-company-to-abandon-open-source/
2•CrankyBear•16m ago•1 comments

Can astrologers gain insights about people from astrological charts?

https://www.clearerthinking.org/post/can-astrologers-use-astrological-charts-to-understand-people...
1•pavel_lishin•17m ago•0 comments

Write stuff down and document things

https://thereabouts.bearblog.dev/why-you-should-write-stuff-down-and-document-things/
2•speckx•19m ago•0 comments

How Older Adults Are Using V.R. To Counter Social Isolation

https://www.nytimes.com/2026/04/15/technology/vr-technology-elderly-community-social-isolation.html
1•mitchbob•20m ago•1 comments

The next evolution of the Agents SDK

https://openai.com/index/the-next-evolution-of-the-agents-sdk/
5•meetpateltech•23m ago•0 comments

What China's Great Green Wall can teach the world

https://www.nature.com/articles/d41586-026-01195-3
4•Brajeshwar•23m ago•0 comments

Graphs That Explain the State of AI in 2026

https://spectrum.ieee.org/state-of-ai-index-2026
3•CarbonCycles•23m ago•0 comments

Microbes make microplastics more likely to form ice in clouds, research reveals

https://phys.org/news/2026-03-microbes-microplastics-ice-clouds-reveals.html
3•PaulHoule•24m ago•0 comments

CPUs Aren't Dead. Gemma2B Out Scored GPT-3.5 Turbo on Test That Made It Famous

https://seqpu.com/CPUsArentDead/
3•fredmendoza•24m ago•0 comments

Can you steal $10k from a locked iPhone? [video]

https://www.youtube.com/watch?v=PPJ6NJkmDAo
2•terramex•26m ago•0 comments

Allbirds shares soar 600% as it pivots from footwear to AI

https://www.cnn.com/2026/04/15/investing/allbirds-pivot-to-ai
5•samsolomon•27m ago•1 comments