A financially motivated threat group is being linked to attacks on build-and-release workflows, a reminder that the most dangerous target in cloud security may be the system trusted to ship the code.