ATALAIA
  1. Home
  2. Resources
  3. Field Guide
Field Guide

Attacks and fixes, station by station.

What goes wrong at each station of the line, and the first thing to do about it.

  1. Design
  2. Toolchain
  3. Source control
  4. Pipeline
  5. Supply chain
  6. Scans
  7. Registry
  8. Deploy
  9. Test
  10. Run

Design

Attack. Business logic abuse: redeeming twice, skipping a payment step, acting for another tenant.

Fix. Threat-model the feature with product and devs; write abuse cases next to user stories.

Toolchain

Attack. A malicious IDE extension or over-trusted AI agent reads keys and pushes code as the developer.

Fix. Allow-list extensions, scope agent and MCP permissions, keep credentials short-lived.

Source control

Attack. A stolen token or a contributor with too much access changes code or workflow files.

Fix. Branch protection, required reviews, CODEOWNERS for workflow files, signed commits where it helps.

Pipeline

Attack. A malicious pull request or third-party action exfiltrates secrets from the runner.

Fix. Pin actions by hash, scope tokens per job, isolate fork builds, prefer ephemeral runners.

Supply chain

Attack. A typosquat, hijacked maintainer or poisoned update arrives as an ordinary dependency.

Fix. One internal proxy, policies for new packages and install scripts, watch critical dependencies.

Scans

Attack. Real findings drown in noise and get ignored.

Fix. Tune rules to the stack, decide what blocks, give every finding an owner.

Registry

Attack. Someone pushes or overwrites an image that then gets deployed.

Fix. Sign at build, attach SBOM and provenance, immutable tags, verify before running.

Deploy

Attack. Anyone can promote anything; emergency access never expires.

Fix. Role-based approvals with evidence; time-limited, logged break-glass; IAM review before release.

Test

Attack. Authorisation bugs ship because nobody tests other roles.

Fix. Automated role-by-endpoint matrix in QA; pentest staging copies; retest every fix.

Run

Attack. An attack path you already know about happens again, unnoticed.

Fix. Turn pentest and bounty findings into detections; check new threats against your stack.