FreshRSS

๐Ÿ”’
โ˜ โ˜† โœ‡ The Hacker News

Malware Attack on CircleCI Engineer's Laptop Leads to Recent Security Incident

By Ravie Lakshmanan โ€” January 14th 2023 at 08:41
DevOps platform CircleCI on Friday disclosed that unidentified threat actors compromised an employee's laptop and leveraged malware to steal their two-factor authentication-backed credentials to breach the company's systems and data last month. The CI/CD service CircleCI said the "sophisticated attack" took place on December 16, 2022, and that the malware went undetected by its antivirus
โ˜ โ˜† โœ‡ Naked Security

CircleCI โ€“ code-building service suffers total credential compromise

By Paul Ducklin โ€” January 9th 2023 at 14:52
They're saying "rotate secrets"... in plain English, they mean "change your credentials". The company has a tool to help you find them all.

โ˜ โ˜† โœ‡ The Hacker News

CircleCI Urges Customers to Rotate Secrets Following Security Incident

By Ravie Lakshmanan โ€” January 5th 2023 at 09:12
DevOps platform CircleCI on Wednesday urged its customers to rotate all their secrets following an unspecified security incident. The company said an investigation is currently ongoing, but emphasized that "there are no unauthorized actors active in our systems." Additional details are expected to be shared in the coming days. "Immediately rotate any and all secrets stored in CircleCI,"
โŒ