• Disclaimer
  • Privacy Policy
  • Copyright Notice
  • Anti Spam Policy
  • Medical Disclaimer
  • DMCA Compliance
  • Terms and Conditions
  • Social Media Disclaimer
  • Amazon Affiliate disclaimer
Sunday, February 18, 2024
  • Login
westvirginiadigitalnews.com
Advertisement
  • Home
  • News
    • PRESS RELEASE
  • Shop
  • BUSINESS
    • CRYPTO
    • ECONOMY
    • FINANCE
    • MARKET
    • MONEY
  • TECH
    • APPS
    • GADGET
    • MOBILE
    • SCIENCE
  • SOCIAL MEDIA
  • ENTERTAINMENT
    • ARTS & THEATER
    • GAMING
    • GAMBLING
    • MOVIE
    • MUSIC
    • SHOWS
    • SPORTS
  • LIFESTYLE
    • CELEBRITY
    • CULTURE
    • Education
    • FASHION
    • FOOD
    • HEALTH
    • HISTORY
    • Nature
    • Religion
    • Shopping
    • TRAVEL
  • REAL ESTATE
  • Blog
  • Classifieds
No Result
View All Result
  • Home
  • News
    • PRESS RELEASE
  • Shop
  • BUSINESS
    • CRYPTO
    • ECONOMY
    • FINANCE
    • MARKET
    • MONEY
  • TECH
    • APPS
    • GADGET
    • MOBILE
    • SCIENCE
  • SOCIAL MEDIA
  • ENTERTAINMENT
    • ARTS & THEATER
    • GAMING
    • GAMBLING
    • MOVIE
    • MUSIC
    • SHOWS
    • SPORTS
  • LIFESTYLE
    • CELEBRITY
    • CULTURE
    • Education
    • FASHION
    • FOOD
    • HEALTH
    • HISTORY
    • Nature
    • Religion
    • Shopping
    • TRAVEL
  • REAL ESTATE
  • Blog
  • Classifieds
No Result
View All Result
westvirginiadigitalnews.com
No Result
View All Result
Home TECH

CircleCI says hackers stole encryption keys and customers’ secrets • TechCrunch

Wisconsin Digital News by Wisconsin Digital News
January 15, 2023
in TECH
0
CircleCI says hackers stole encryption keys and customers’ secrets • TechCrunch
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter


CircleCi, a software company whose products are popular with developers and software engineers, confirmed that some customers’ data was stolen in a data breach last month.

The company said in a detailed blog post on Friday that it identified the intruder’s initial point of access as an employee’s laptop that was compromised with malware, allowing the theft of session tokens used to keep the employee logged in to certain applications, even though their access was protected with two-factor authentication.

The company took the blame for the compromise, calling it a “systems failure,” adding that its antivirus software failed to detect the token-stealing malware on the employee’s laptop.

Session tokens allow a user to stay logged in without having to keep re-entering their password or re-authorizing using two-factor authentication each time. But a stolen session token allows an intruder to gain the same access as the account holder without needing their password or two-factor code. As such, it can be difficult to differentiate between a session token of the account owner, or a hacker who stole the token.

CircleCi said the theft of the session token allowed the cybercriminals to impersonate the employee and gain access to some of the company’s production systems, which store customer data.

“Because the targeted employee had privileges to generate production access tokens as part of the employee’s regular duties, the unauthorized third party was able to access and exfiltrate data from a subset of databases and stores, including customer environment variables, tokens, and keys,” said Rob Zuber, the company’s chief technology officer. Zuber said the intruders had access from December 16 through January 4.

Zuber said that while customer data was encrypted, the cybercriminals also obtained the encryption keys able to decrypt customer data. “We encourage customers who have yet to take action to do so in order to prevent unauthorized access to third-party systems and stores,” Zuber added.

Several customers have already informed CircleCi of unauthorized access to their systems, Zuber said.

The post-mortem comes days after the company warned customers to rotate “any and all secrets” stored in its platform, fearing that hackers had stolen its customers’ code and other sensitive secrets used for access to other applications and services.

Zuber said that CircleCi employees who retain access to production systems “have added additional step-up authentication steps and controls,” which should prevent a repeat-incident, likely by way of using hardware security keys.

The initial point of access — the token-stealing on an employee’s laptop — bears some resemblance to how the password manager giant LastPass was hacked, which also involved an intruder targeting an employee’s device, though it’s not known if the two incidents are linked. LastPass confirmed in December that its customers’ encrypted password vaults were stolen in an earlier breach. LastPass said the intruders had initially compromised an employee’s device and account access, allowing them to break into LastPass’ internal developer environment.

Updated headline to better reflect the customer data that was taken.



Source link

Wisconsin Digital News

Wisconsin Digital News

Related Posts

Feds open second probe into Fisker’s Ocean SUV after rollaway complaints
TECH

Feds open second probe into Fisker’s Ocean SUV after rollaway complaints

February 16, 2024
Sony just let slip a Final Fantasy VII Rebirth playable demo is imminent
TECH

Sony just let slip a Final Fantasy VII Rebirth playable demo is imminent

February 6, 2024
IT budgets should increase in 2024, but it still could be tough going for startups
TECH

IT budgets should increase in 2024, but it still could be tough going for startups

December 18, 2023
Next Post
Scaramucci Invests in Crypto Firm Set Up by Ex-FTX US Head

Scaramucci Invests in Crypto Firm Set Up by Ex-FTX US Head

Shopping mall vlogs #lulumall #youtubeshorts #ytshorts #trendingshorts

Shopping mall vlogs #lulumall #youtubeshorts #ytshorts #trendingshorts

A historic meeting of Orthodox Christian scholars convenes to confront divisions and war

A historic meeting of Orthodox Christian scholars convenes to confront divisions and war

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Follow Us

Recommended

Gateway 14 review: it’s blue!

Gateway 14 review: it’s blue!

10 months ago
Interscope Co-Founder Jimmy Iovine Facing Lawsuit Over Alleged Sexual Abuse

Interscope Co-Founder Jimmy Iovine Facing Lawsuit Over Alleged Sexual Abuse

3 months ago
When I Sing Everyone Cry

When I Sing Everyone Cry

1 year ago
Tory Lanez Found Guilty in Megan Thee Stallion Shooting

Tory Lanez Found Guilty in Megan Thee Stallion Shooting

1 year ago

Instagram

    Please install/update and activate JNews Instagram plugin.

Categories

  • APPS
  • ARTS & THEATER
  • Blog
  • BUSINESS
  • CELEBRITY
  • CRYPTO
  • CULTURE
  • ECONOMY
  • Education
  • ENTERTAINMENT
  • FASHION
  • FINANCE
  • FOOD
  • GADGET
  • Gambling
  • GAMING
  • HEALTH
  • HISTORY
  • LIFESTYLE
  • MARKET
  • MOBILE
  • MONEY
  • MOVIE
  • MUSIC
  • Nature
  • News
  • PRESS RELEASE
  • REAL ESTATE
  • Religion
  • SCIENCE
  • Shopping
  • SHOWS
  • SOCIAL MEDIA
  • SPORTS
  • TECH
  • TRAVEL
  • Uncategorized
No Result
View All Result

Fivver Ads

Madison
◉
18°
Mostly Cloudy
6:56 am5:35 pm EST
Feels like: 10°F
Wind: 4mph W
Humidity: 77%
Pressure: 29.9"Hg
UV index: 0
SunMonTue
30/18°F
23/12°F
37/25°F
Weather forecast Madison, New York ▸

Highlights

From Hiring To Retirement: How To Automate Your HR Processes

Protecting the Puget Sound through Activism and Investment — The Nature Conservancy in Washington

Exercising When Sick: A Good Move?

Paramore Reject Tennessee State Honor in Solidarity With Allison Russell, Citing “Blatant Racism” of House Republicans

Who is Bing Worthington? 5 Things on Snoop Dogg’s Late Brother – Hollywood Life

Heart Risks After Pregnancy-Related High Blood Pressure in Latinas

Trending

Have a Good Weekend. | Cup of Jo
LIFESTYLE

Have a Good Weekend. | Cup of Jo

by Wisconsin Digital News
February 18, 2024
0

What are you up to this weekend? We’re hanging out with my mom, who is now an...

Top 3 Apps To Buy/Invest In US Stocks From India #shorts

Top 3 Apps To Buy/Invest In US Stocks From India #shorts

February 18, 2024
Dave Portnoy Regrets Selling Bitcoin — Wishes Barstool Invested $10 Million in BTC

Dave Portnoy Regrets Selling Bitcoin — Wishes Barstool Invested $10 Million in BTC

February 18, 2024
From Hiring To Retirement: How To Automate Your HR Processes

From Hiring To Retirement: How To Automate Your HR Processes

February 18, 2024
Protecting the Puget Sound through Activism and Investment — The Nature Conservancy in Washington

Protecting the Puget Sound through Activism and Investment — The Nature Conservancy in Washington

February 18, 2024
Wisconsin Digital News

Follow us on social media:

Recent News

  • Have a Good Weekend. | Cup of Jo
  • Top 3 Apps To Buy/Invest In US Stocks From India #shorts
  • Dave Portnoy Regrets Selling Bitcoin — Wishes Barstool Invested $10 Million in BTC

Category

  • APPS
  • ARTS & THEATER
  • Blog
  • BUSINESS
  • CELEBRITY
  • CRYPTO
  • CULTURE
  • ECONOMY
  • Education
  • ENTERTAINMENT
  • FASHION
  • FINANCE
  • FOOD
  • GADGET
  • Gambling
  • GAMING
  • HEALTH
  • HISTORY
  • LIFESTYLE
  • MARKET
  • MOBILE
  • MONEY
  • MOVIE
  • MUSIC
  • Nature
  • News
  • PRESS RELEASE
  • REAL ESTATE
  • Religion
  • SCIENCE
  • Shopping
  • SHOWS
  • SOCIAL MEDIA
  • SPORTS
  • TECH
  • TRAVEL
  • Uncategorized
  • Disclaimer
  • Privacy Policy
  • Copyright Notice
  • Anti Spam Policy
  • Medical Disclaimer
  • DMCA Compliance
  • Terms and Conditions
  • Social Media Disclaimer
  • Amazon Affiliate disclaimer

© 2022 Wisconsindigitalnews

No Result
View All Result
  • Home
  • News
    • PRESS RELEASE
  • Shop
  • BUSINESS
    • CRYPTO
    • ECONOMY
    • FINANCE
    • MARKET
    • MONEY
  • TECH
    • APPS
    • GADGET
    • MOBILE
    • SCIENCE
  • SOCIAL MEDIA
  • ENTERTAINMENT
    • ARTS & THEATER
    • GAMING
    • GAMBLING
    • MOVIE
    • MUSIC
    • SHOWS
    • SPORTS
  • LIFESTYLE
    • CELEBRITY
    • CULTURE
    • Education
    • FASHION
    • FOOD
    • HEALTH
    • HISTORY
    • Nature
    • Religion
    • Shopping
    • TRAVEL
  • REAL ESTATE
  • Blog
  • Classifieds

© 2022 Wisconsindigitalnews

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
7ff4be7246cf13968ba60ea4ed8fa54c98d8c56d