GitHub Confirms Internal Breach
The company said it is still working through the intrusion but does not believe any customer repositories or data was affected at this point.
All topics
The company said it is still working through the intrusion but does not believe any customer repositories or data was affected at this point.
This week we dig deep into the Vercel intrusion that emerged last weekend, how it happened, what the response was, and what the downstream effects may be for defenders. Then we talk about CISA’s bizarre delayed response to the Axios npm compromise and what it signals about the agency’s capabilities going forward.
The incident came to light on Sunday and the company says it has brought in an incident response provider to investigate the intrusion. Details of the intrusion are scant at this point.
In the wake of the disclosure of a serious intrusion at F5 that reportedly lasted about a year, we talk about the details of the disclosure, the potential link to Chinese state actors, the fallout from the attackers’ access to source code and bug reports, and what this could mean in the long term.
The company discovered the intrusion in August but did not say when the attackers first gained access to F5’s systems or how long they had access.
This week brings some new insights into the origins and length of the Cl0p extortion attacks tied to the Oracle E-Business Suite vulnerability, big surges in scanning for Cisco ASA, Palo Alto, and Fortinet devices, and a huge upgrade to Apple bug bounty payouts.