Design
Attack. Business logic abuse: redeeming twice, skipping a payment step, acting for another tenant.
Fix. Threat-model the feature with product and devs; write abuse cases next to user stories.
Toolchain
Attack. A malicious IDE extension or over-trusted AI agent reads keys and pushes code as the developer.
Fix. Allow-list extensions, scope agent and MCP permissions, keep credentials short-lived.
Source control
Attack. A stolen token or a contributor with too much access changes code or workflow files.
Fix. Branch protection, required reviews, CODEOWNERS for workflow files, signed commits where it helps.
Pipeline
Attack. A malicious pull request or third-party action exfiltrates secrets from the runner.
Fix. Pin actions by hash, scope tokens per job, isolate fork builds, prefer ephemeral runners.
Supply chain
Attack. A typosquat, hijacked maintainer or poisoned update arrives as an ordinary dependency.
Fix. One internal proxy, policies for new packages and install scripts, watch critical dependencies.
Scans
Attack. Real findings drown in noise and get ignored.
Fix. Tune rules to the stack, decide what blocks, give every finding an owner.
Registry
Attack. Someone pushes or overwrites an image that then gets deployed.
Fix. Sign at build, attach SBOM and provenance, immutable tags, verify before running.
Deploy
Attack. Anyone can promote anything; emergency access never expires.
Fix. Role-based approvals with evidence; time-limited, logged break-glass; IAM review before release.
Test
Attack. Authorisation bugs ship because nobody tests other roles.
Fix. Automated role-by-endpoint matrix in QA; pentest staging copies; retest every fix.
Run
Attack. An attack path you already know about happens again, unnoticed.
Fix. Turn pentest and bounty findings into detections; check new threats against your stack.