<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Ci-Cd-Security on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/ci-cd-security/</link><description>Recent content in Ci-Cd-Security on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Sun, 15 Jun 2025 13:30:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/ci-cd-security/index.xml" rel="self" type="application/rss+xml"/><item><title>Arch Linux AUR Locked Down After Malicious Package Wave</title><link>https://zxcloudsecurity.co.uk/posts/arch-linux-aur-lockdown-malicious-packages-supply-chain/</link><pubDate>Mon, 15 Jun 2026 13:30:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/arch-linux-aur-lockdown-malicious-packages-supply-chain/</guid><description>Arch Linux freezes AUR signups after attackers flood the community repo with poisoned packages. Learn the supply chain risks and mitigations for cloud team</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/security/2026/06/15/arch-linux-locks-down-aur-signups-amid-wave-of-malicious-commits/5255511">The Register — Security</a></p>
<hr>
<p>Arch Linux has temporarily frozen new account registrations on the Arch User Repository (AUR) after attackers submitted a wave of malicious package updates designed to compromise systems that install from the community-maintained repository. AUR packages are not officially vetted, making them a high-value target for supply chain attacks. This incident highlights the ongoing risk of depending on community repositories in build pipelines and development environments.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Audit any CI/CD pipelines or developer workstations that pull packages from AUR and consider banning or sandboxing AUR usage entirely in corporate environments; where AUR is genuinely required, pin packages to known-good commit hashes and implement runtime integrity monitoring to detect unexpected binary behaviour post-install.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/security/2026/06/15/arch-linux-locks-down-aur-signups-amid-wave-of-malicious-commits/5255511">Arch Linux locks down AUR signups amid wave of malicious commits</a></p>
]]></content:encoded></item></channel></rss>