การยินยอมใช้คุกกี้

COOKIE CONSENT

เราใช้คุกกี้เพื่อปรับปรุงประสบการณ์การใช้งาน วิเคราะห์การเข้าใช้เว็บไซต์ และนำเสนอเนื้อหาที่เกี่ยวข้อง ท่านสามารถเลือกประเภทคุกกี้ที่ยินยอมได้ ดูรายละเอียดเพิ่มเติมใน ประกาศคุกกี้

Data Breach

Supply Chain Breach at CrowdSec Exposes Private GitHub Repositories

FORTSECURE GLOBAL· 2026-09-23🛰 Dark Reading
#Supply Chain#GitHub#OAuth#Data Breach
Supply Chain Breach at CrowdSec Exposes Private GitHub Repositories

CrowdSec recently suffered a data breach involving 170 private repositories after attackers exploited an OAuth token compromised through a supply chain attack.

Analysis of the Supply Chain Attack

The security firm CrowdSec has confirmed an unauthorized access incident resulting from the compromise of a former employee's workstation. Attackers leveraged an OAuth token obtained through the 'TanStack' npm supply chain attack, which enabled them to gain access to 170 private GitHub repositories. This incident highlights the growing risks associated with third-party dependencies and the importance of securing developer environments against sophisticated malware that can harvest credentials and session tokens.

Strengthening Developer Security

To mitigate the risk of supply chain-originated breaches, companies must implement strict revocation policies for former employee credentials and session tokens. All developers should utilize hardware security keys for access to critical source code management platforms like GitHub. Furthermore, adopting tools that monitor and scan dependencies for malicious code in real-time can prevent compromised packages from infecting internal development systems. Organizations should also treat internal source code repositories as high-value assets with strict access controls and continuous auditing.


แหล่งที่มา: Dark Reading เผยแพร่ครั้งแรก: Tue, 22 Sep 2026 17:32:49 GMT บทความต้นฉบับ: อ่านต้นฉบับ

Source Attribution

แหล่งที่มา: Dark Reading

เผยแพร่ครั้งแรก: Tue, 22 Sep 2026 17:32:49 GMT

บทความต้นฉบับ: https://www.darkreading.com/cyberattacks-data-breaches/shai-hulud-attack-cyber-firm-crowdsec-github-data

อ่านบทความต้นฉบับ ↗
ถูกใจบทความนี้

* Facebook / LinkedIn ไม่อนุญาตให้ใส่ข้อความให้ล่วงหน้า — กดปุ่มจะคัดลอกข้อความให้ก่อน เปิดหน้าแชร์แล้ววาง (paste) ได้เลย พรีวิวการ์ดจะแสดงอัตโนมัติเมื่อวางลิงก์

← กลับไปหน้า Blog