On Saturday, July 6, Canonical's GitHub account, the developer of the popular Linux Ubuntu distribution,…
“The leak was caused by a former business partner of the company, the analytical platform Waydev. Due to Waydev’s negligence, attackers were able to gain unauthorized access to Dave’s user data”, – said later Dave representatives.
Now the Waydev developers have confirmed that earlier this month, unknown hackers have stolen the company’s GitHub and GitLab OAuth tokens.
The fact is that the Waydev platform is used to monitor the results of the work of software developers by analyzing the Git codebases. For this, Waydev has a dedicated app on GitHub and GitLab. When users install this application, Waydev receives an OAuth token that can be used to access clients’ projects on GitHub or GitLab. Waydev stores tokens in its database and uses them daily to generate analytical reports for clients.
“Hackers discovered a vulnerability and performed SQL injection to get to Waydev database and steal tokens. The attackers then used the tokens to navigate to codebases of other companies and gain access to their projects”, – said Waydev representatives.
The company says it discovered the attack on July 3, 2020 and fixed used by the attackers vulnerability on the same day. Waydev engineers also worked with GitHub and GitLab to revoke all affected OAuth tokens.
Let me also remind you that previously unknown hackers compromised Canonical account on GitHub.
Waydev is now confident that hackers have gained access to codebases of a small number of customers. So, so far only two victims are known – the already mentioned Dave company and the Flood.io software testing service.
Now the company is investigating the incident together with law enforcement agencies and information security experts from Bit Sentinel.
To make it easier for potential victims to detect suspicious activity, Waydev representatives have already released indicators of compromise associated with unknown attackers, including email addresses, IP addresses and user agent.
By the way, do you remember that GitHub imposes sanctions on accounts of developers from Iran, the Crimea and Syria?
News-bpudepi.today is a domain that tries to trick you into subscribing to its browser notifications…
Doguhtam.xyz is a site that tries to trick you into subscribing to its browser notifications…
News-xlixoti.com is a site that tries to force you into subscribing to its browser notifications…
Ducesousightion.com is a domain that tries to trick you into clik to its browser notifications…
News-xlabica.live is a domain that tries to trick you into clik to its browser notifications…
Mergechain.co.in is a site that tries to trick you into subscribing to its browser notifications…