- CLOUD0%
BlockBeats News, May 20: Grafana Labs released a security update, stating that the company confirmed on May 16 that it had experienced a targeted network attack. The attacker gained unauthorized access through a GitHub repository and downloaded its codebase, then issued a ransom demand.
The company stated that the incident stemmed from an attack involving the TanStack npm supply chain. After gaining initial access, the attacker further exploited a missed GitHub workflow token to gain entry into the company's internal repository environment.
Grafana Labs emphasized that the current investigation has not found any impact on customer production systems or the Grafana Cloud platform. The incident was limited to the company's GitHub environment, including source code and some internal collaborative repository content, but the code was not altered.
The company noted that the downloaded data may contain more than just the source code, possibly including internal operational information, business contact names, and emails, but not production system data.
The attacker subsequently demanded a ransom to prevent code disclosure, but Grafana Labs stated that it has refused to pay and is cooperating with law enforcement agencies in the investigation.
The company has now implemented a series of security measures, including rotating automatic tokens, enhancing monitoring, auditing commit logs, and strengthening CI/CD security. It also mentioned that a comprehensive post-incident report will be released.
면책 조항: 현재 콘텐츠는 제3자 관점에서 제공되거나 제3자 관점에서 AI가 직접 번역한 것입니다. CoinEx는 콘텐츠의 진위성, 정확성, 독창성을 보장하지 않으며 CoinEx의 투자 조언으로 간주하지 않습니다. 암호화폐 가격은 변동성이 크므로 잠재적인 위험에 유의하시기 바랍니다.
- 코인가격24시간 변동