Grafana says hackers hit its GitHub environment, demand ransom to prevent codebase release — but it's…

https://cdn.mos.cms.futurecdn.net/ioiGboNmGxjo77hGKRFefJ-1980-80.jpg
  • Grafana confirms its GitHub environment was accessed with a stolen token and its codebase exfiltrated
  • Maintainers stressed no customer data or systems were impacted and security measures were reinforced
  • A group called CoinbaseCartel claimed responsibility, linking the incident to broader ransomware activity

Popular open source software platform Grafana has confirmed its GitHub environment was compromised and its codebase exfiltrated.

In a breach notification, maintainers Grafana Labs explained that an unauthorized third party used a token to access its GitHub environment, where they were able to download the contents.

While it didn’t explain how the token was nabbed, Grafana said that the initial investigation “determined that no customer data or personal information was accessed during this incident,” and that there is no evidence that the breach impacted customer systems or operations.

How to stay safe

“We immediately initiated forensic analysis and we believe we’ve identified the source of the credential leak,”...

Copyright of this story solely belongs to techradar.com. To see the full text click HERE

Read more

http://www.techmeme.com/img/techmeme_sq328.png

GitHub says it's investigating “unauthorized access” to its internal repositories, and there's no proof of customer data outside its repositories being impacted

Sponsor Posts Niantic Spatial: World models need real-world data — Scaniverse is the gateway to spatial services — self-serve and built for AI and robotics. Large-area 3D reconstruction from 360° cameras and precise localization, anywhere machines operate. Protecting your Cloud Applications Data — Backing up Office 365, Google Workspace, Dropbox & Salesforce data