Grafana says hackers hit its GitHub environment, demand ransom to prevent codebase release — but it's…
- Grafana confirms its GitHub environment was accessed with a stolen token and its codebase exfiltrated
- Maintainers stressed no customer data or systems were impacted and security measures were reinforced
- A group called CoinbaseCartel claimed responsibility, linking the incident to broader ransomware activity
Popular open source software platform Grafana has confirmed its GitHub environment was compromised and its codebase exfiltrated.
In a breach notification, maintainers Grafana Labs explained that an unauthorized third party used a token to access its GitHub environment, where they were able to download the contents.
While it didn’t explain how the token was nabbed, Grafana said that the initial investigation “determined that no customer data or personal information was accessed during this incident,” and that there is no evidence that the breach impacted customer systems or operations.
How to stay safe
“We immediately initiated forensic analysis and we believe we’ve identified the source of the credential leak,”...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE