top of page

InvisiRisk Blog Posts


Hackerbot-Claw: AI-Driven Pull Request Exploits in GitHub Actions CI/CD
Date Observed : Late February 2026 Ecosystem : GitHub Actions CI/CD Attack Type : Pull-request triggered workflow exploitation → Remote Code Execution (RCE) → Token theft Key Takeaways: Hackerbot-Claw exploited misconfigured GitHub Actions workflows using malicious pull-request (PR) input. The attack executed inside the CI/CD build environment, not in merged code. Once tokens were exposed, attackers could modify repositories and publish artifacts. A recent campaign attributed

Pranesh Shrestha
3 days ago4 min read


InvisiRisk Unveils Groundbreaking Build Security AI Agent
InvisiRisk, Inc. is excited to announce the launch of its revolutionary Build Security AI Agent, designed to transform the security landscape of software supply chains. This innovative solution leverages advanced artificial intelligence to provide unparalleled protection for CI/CD pipelines, ensuring the integrity and security of software development processes.

InvisiRisk, Inc.
May 8, 20252 min read


InvisiRisk Announces the Launch of its Innovative Governance, Risk and Compliance Platform for the Software Supply Chain
Announcement about the launch of our innovative Governance, Risk, and Compliance (GRC) platform for the software supply chain.

InvisiRisk, Inc.
Dec 10, 20243 min read
bottom of page