Tag Archive for: Larger

CircleCI probe links malware placed on engineer’s laptop to larger breach


CircleCI said an unauthorized third-party leveraged malware on the laptop of one of its engineers to steal a valid 2FA-backed single-sign-on session, according to highly anticipated report stemming from a security incident disclosed earlier this month. 

The engineer’s laptop was compromised on Dec. 16, but the company’s antivirus software failed to detect the malware, the company said. 

“Our investigation indicates that the malware was able to execute session cookie theft, enabling them to impersonate the targeted employee in a remote location and then escalate across to a subset of our production systems,” CircleCI CTO Rob Zuber explained in the updated blog post.

Less than five customers have said they experienced unauthorized access to third-party systems, the company said.

The engineer had privileges to generate production access tokens, so the third-party was able to exfiltrate data from a subset of databases and stores, including customer environment variables, tokens and keys, according to the blog post. 

CircleCI strongly defended the employee in the report, emphasizing the incident was not due to the actions of any one person, but a collective failure of various systems. 

“While one employee’s laptop was exploited through this sophisticated attack, a security incident is a systems failure,” Zuber said in the blog post. “Our responsibility as an organization is to build layers of safeguards that protect against all attack vectors.”

The threat actor did reconnaissance activity on Dec. 19 and the exfiltration took place on Dec. 22. 

Though all the data exfiltrated was encrypted at rest, the third party extracted encryption keys from a running process, enabling them to potentially access the encrypted data,” Zuber said.

By Dec. 29, the company was alerted to suspicious GitHub OAuth activity and realized on Dec. 30 a Github OAuth token belonging to one of its customers was compromised by an unauthorized party. 

The customer resolved the issue, but on Dec. 31 CircleCI decided to rotate all GitHub OAuth tokens on behalf of customers. 

CircleCI said it considers the platform safe for customers to…

Source…

Smart-Lock Hacks Point to Larger IoT Problems

Two recent reports on smart-locks vulnerabilities show that IoT vendors have a bigger job to do in ensuring their products are safely deployed and configured.
mac hacker – read more

Kmart store closures may be part of a larger trend – wwlp.com


wwlp.com

Kmart store closures may be part of a larger trend
wwlp.com
FILE – In this Tuesday, Dec. 27, 2011 file photo, pedestrians pass a Kmart store location in New York. On Friday, Oct. 10, 2014, Sears Holdings Corp. announced that it detected a data breach at its Kmart stores that started in August 2014, affecting

and more »

data breach – Google News

Sundown Exploit Kit ‘Larger Threat Than People Realize’ – Threatpost


Threatpost

Sundown Exploit Kit 'Larger Threat Than People Realize'
Threatpost
Now, Cisco Talos security researchers are bracing for new entrants to fill the void, starting with the Sundown exploit kit. Over the past six months, Sundown has become a significant threat responsible for a large number of infections. Researcher Nick
Sundown Becomes a Rising Star on the EK Scene – Infosecurity …Infosecurity Magazine

all 2 news articles »

“exploit kit” – read more