Missouri Digital News
  • Home
  • News
    • PRESS RELEASE
  • Shop
  • BUSINESS
    • CRYPTO
    • ECONOMY
    • FINANCE
    • MARKET
    • MONEY
  • TECH
    • APPS
    • GADGET
    • MOBILE
    • SCIENCE
  • SOCIAL MEDIA
  • ENTERTAINMENT
    • ARTS & THEATER
    • GAMING
    • GAMBLING
    • MOVIE
    • MUSIC
    • SHOWS
    • SPORTS
  • LIFESTYLE
    • CELEBRITY
    • CULTURE
    • Education
    • FASHION
    • FOOD
    • HEALTH
    • HISTORY
    • Nature
    • Religion
    • Shopping
    • TRAVEL
  • REAL ESTATE
  • Blog
  • Classifieds
No Result
View All Result
Missouri Digital News
  • Home
  • News
    • PRESS RELEASE
  • Shop
  • BUSINESS
    • CRYPTO
    • ECONOMY
    • FINANCE
    • MARKET
    • MONEY
  • TECH
    • APPS
    • GADGET
    • MOBILE
    • SCIENCE
  • SOCIAL MEDIA
  • ENTERTAINMENT
    • ARTS & THEATER
    • GAMING
    • GAMBLING
    • MOVIE
    • MUSIC
    • SHOWS
    • SPORTS
  • LIFESTYLE
    • CELEBRITY
    • CULTURE
    • Education
    • FASHION
    • FOOD
    • HEALTH
    • HISTORY
    • Nature
    • Religion
    • Shopping
    • TRAVEL
  • REAL ESTATE
  • Blog
  • Classifieds
No Result
View All Result
Missouri Digital News
No Result
View All Result
Home TECH

CircleCI says hackers stole encryption keys and customers’ secrets • TechCrunch

Missouri Digital News by Missouri Digital News
January 15, 2023
in TECH
0
CircleCI says hackers stole encryption keys and customers’ secrets • TechCrunch
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter


You might also like

Tinder redesigns profile pages with prompts, info tags and quiz

Polestar tackles softening EV demand with new tech and next-gen vehicles

The best drawing tablets to buy right now

CircleCi, a software company whose products are popular with developers and software engineers, confirmed that some customers’ data was stolen in a data breach last month.

The company said in a detailed blog post on Friday that it identified the intruder’s initial point of access as an employee’s laptop that was compromised with malware, allowing the theft of session tokens used to keep the employee logged in to certain applications, even though their access was protected with two-factor authentication.

The company took the blame for the compromise, calling it a “systems failure,” adding that its antivirus software failed to detect the token-stealing malware on the employee’s laptop.

Session tokens allow a user to stay logged in without having to keep re-entering their password or re-authorizing using two-factor authentication each time. But a stolen session token allows an intruder to gain the same access as the account holder without needing their password or two-factor code. As such, it can be difficult to differentiate between a session token of the account owner, or a hacker who stole the token.

CircleCi said the theft of the session token allowed the cybercriminals to impersonate the employee and gain access to some of the company’s production systems, which store customer data.

“Because the targeted employee had privileges to generate production access tokens as part of the employee’s regular duties, the unauthorized third party was able to access and exfiltrate data from a subset of databases and stores, including customer environment variables, tokens, and keys,” said Rob Zuber, the company’s chief technology officer. Zuber said the intruders had access from December 16 through January 4.

Zuber said that while customer data was encrypted, the cybercriminals also obtained the encryption keys able to decrypt customer data. “We encourage customers who have yet to take action to do so in order to prevent unauthorized access to third-party systems and stores,” Zuber added.

Several customers have already informed CircleCi of unauthorized access to their systems, Zuber said.

The post-mortem comes days after the company warned customers to rotate “any and all secrets” stored in its platform, fearing that hackers had stolen its customers’ code and other sensitive secrets used for access to other applications and services.

Zuber said that CircleCi employees who retain access to production systems “have added additional step-up authentication steps and controls,” which should prevent a repeat-incident, likely by way of using hardware security keys.

The initial point of access — the token-stealing on an employee’s laptop — bears some resemblance to how the password manager giant LastPass was hacked, which also involved an intruder targeting an employee’s device, though it’s not known if the two incidents are linked. LastPass confirmed in December that its customers’ encrypted password vaults were stolen in an earlier breach. LastPass said the intruders had initially compromised an employee’s device and account access, allowing them to break into LastPass’ internal developer environment.

Updated headline to better reflect the customer data that was taken.



Source link

Share30Tweet19
Missouri Digital News

Missouri Digital News

Recommended For You

Tinder redesigns profile pages with prompts, info tags and quiz

by Missouri Digital News
November 20, 2023
0
Tinder redesigns profile pages with prompts, info tags and quiz

Tinder is revamping its profile pages to make them more informative and create easier starting points for conversations. The company is launching features like profile prompts as conversation...

Read more

Polestar tackles softening EV demand with new tech and next-gen vehicles

by Missouri Digital News
November 11, 2023
0
Polestar tackles softening EV demand with new tech and next-gen vehicles

Polestar showcased this week its vision for the future: new tech and next-generation vehicles that the Swedish EV company owned by China’s Geely Holdings hopes will spark sales...

Read more

The best drawing tablets to buy right now

by Missouri Digital News
November 2, 2023
0
The best drawing tablets to buy right now

Drawing tablets (also known as graphics tablets or art tablets) aren’t just for digital creatives like graphic designers, artists, and photo editors. They’re useful for gamers, office workers,...

Read more

Aleph is building a platform to reconcile disparate financial data

by Missouri Digital News
October 24, 2023
0
Aleph is building a platform to reconcile disparate financial data

As cloud-based software becomes the norm for many functions inside of modern businesses, data silos are growing into an outsize problem. This is particularly true in the financial...

Read more

The best apps and systems for tracking movies, music, books, and more

by Missouri Digital News
October 15, 2023
0
The best apps and systems for tracking movies, music, books, and more

Hi, friends! Welcome to Installer No. 10, your guide to the best and Verge-iest stuff in the world. (If you’re new here, hooray! I’m so happy you’re here,...

Read more
Next Post
Shops at Pembroke Gardens, FL USA [4K] Mall Walk | Walk Tour

Shops at Pembroke Gardens, FL USA [4K] Mall Walk | Walk Tour

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Jefferson City
◉
34°
Clear
7:05 am4:48 pm CST
Feels like: 34°F
Wind: 1mph SSW
Humidity: 65%
Pressure: 30.1"Hg
UV index: 0
ThuFriSat
54/43°F
48/36°F
52/36°F
Weather forecast Jefferson City, Missouri ▸

Fivver Ads

Related News

Here’s What Will Happen to Queen Elizabeth II’s Corgis After Her Death

Here’s What Will Happen to Queen Elizabeth II’s Corgis After Her Death

September 11, 2022
New $100 Diablo IV ‘Collector’s Box’ Doesn’t Include Game

New $100 Diablo IV ‘Collector’s Box’ Doesn’t Include Game

December 17, 2022
FDA Approves Novel Drug to Treat Moderate to Severe Hot Flashes … – FDA.gov

Small developers on the App Store grew revenue by 71 percent from … – Apple

May 14, 2023
Nick Cannon Takes Abby De La Rosa on “Unforgettable” Beachy Babymoon

Nick Cannon Takes Abby De La Rosa on “Unforgettable” Beachy Babymoon

October 5, 2022
Shareholder Alert: Robbins LLP Informs Investors of Class Action Against Palantir Technologies Inc. (PLTR)

Shareholder Alert: Robbins LLP Informs Investors of Class Action Against Palantir Technologies Inc. (PLTR)

September 20, 2022
Have a Delicious Weekend. | Cup of Jo

Have a Delicious Weekend. | Cup of Jo

January 21, 2023
FDA Approves Novel Drug to Treat Moderate to Severe Hot Flashes … – FDA.gov

Washington boy plummets 20 feet deep into well during recess – Fox News

June 2, 2023
✨ Full Show Disneyland Paris Annual Pass Party: Jungle Book Jive special edition 2023

✨ Full Show Disneyland Paris Annual Pass Party: Jungle Book Jive special edition 2023

April 26, 2023
Can We Beat These FAKE AMONG US APPS!? (FUNNY MOMENTS!)

Can We Beat These FAKE AMONG US APPS!? (FUNNY MOMENTS!)

May 5, 2023
Press Release | Press Releases | Newsroom

Press Release | Press Releases | Newsroom

August 19, 2022
‘General Hospital’ Star Dies at 50 – Hollywood Life

‘General Hospital’ Star Dies at 50 – Hollywood Life

November 1, 2023
Where Do You Feel a Cultural Belonging?

Where Do You Feel a Cultural Belonging?

May 23, 2023
What the Hell Happened This Week? Week of 10/17/2022

What the Hell Happened This Week? Week of 10/17/2022

December 11, 2022
iPhone 15 ‘Ultra’ could replace next year’s Pro Max model

iPhone 15 ‘Ultra’ could replace next year’s Pro Max model

September 25, 2022
Stroke Risk in Young and Middle-Aged Adults

Stroke Risk in Young and Middle-Aged Adults

December 22, 2022
Missouri Digital News

CATEGORIES

  • APPS
  • ARTS & THEATER
  • BUSINESS
  • CELEBRITY
  • CRYPTO
  • CULTURE
  • ECONOMY
  • Education
  • ENTERTAINMENT
  • FASHION
  • FINANCE
  • FOOD
  • GADGET
  • Gambling
  • GAMING
  • HEALTH
  • HISTORY
  • LIFESTYLE
  • MARKET
  • MOBILE
  • MONEY
  • MOVIE
  • MUSIC
  • Nature
  • News
  • PRESS RELEASE
  • REAL ESTATE
  • Religion
  • SCIENCE
  • Shopping
  • SHOWS
  • SPORTS
  • TECH
  • TRAVEL
FASHION

5 Plus Size Peloton User Reviews That Are *Actually* Helpful

November 26, 2023
Religion

‘What We’re Grateful For’ — GetReligion

November 26, 2023
PRESS RELEASE

Mendocino College to host annual ceramic sale on Dec. 1 (press … – The Mendocino Voice

November 26, 2023

© 2023 Missouri Digital News

No Result
View All Result
  • Home
  • News
    • PRESS RELEASE
  • Shop
  • BUSINESS
    • CRYPTO
    • ECONOMY
    • FINANCE
    • MARKET
    • MONEY
  • TECH
    • APPS
    • GADGET
    • MOBILE
    • SCIENCE
  • SOCIAL MEDIA
  • ENTERTAINMENT
    • ARTS & THEATER
    • GAMING
    • GAMBLING
    • MOVIE
    • MUSIC
    • SHOWS
    • SPORTS
  • LIFESTYLE
    • CELEBRITY
    • CULTURE
    • Education
    • FASHION
    • FOOD
    • HEALTH
    • HISTORY
    • Nature
    • Religion
    • Shopping
    • TRAVEL
  • REAL ESTATE
  • Blog
  • Classifieds

© 2023 Missouri Digital News

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?