Skip to content

Cyber Security And Bitcoin Blockchain News

The World

  • Funding Rates Fall To Yearly Lows Following Bitcoin’s Fall Below $29,000 bitcoin news
  • SHIELDS UP in bite sized chunks cyber security news
  • U.S. Proposes $1 Million Fine on Colonial Pipeline for Safety Violations After Cyberattack cyber security news
  • Chinese Hackers Caught Stealing Intellectual Property from Multinational Companies cyber security news
  • Russian Crypto Mining Giant Bitriver Considers Challenging US Sanctions – Mining Bitcoin News bitcoin news
  • Square Enix Closes $300 Million Sale of Western Studios to Bankroll Blockchain Pivot – News Bitcoin News bitcoin news
  • International Monetary Fund to Assist El Salvador in Compiling Bitcoin Adoption Statistics – Bitcoin News bitcoin news
  • Crypto Carnage Causes Flight To Bitcoin Safe Haven, Dominance Demonstrates bitcoin news

Heroku Forces User Password Resets Following GitHub OAuth Token Theft

Posted on May 5, 2022 By root


Heroku Forces User Password Resets

Salesforce-owned subsidiary Heroku on Thursday acknowledged that the theft of GitHub integration OAuth tokens further involved unauthorized access to an internal customer database.

The company, in an updated notification, revealed that a compromised token was abused to breach the database and “exfiltrate the hashed and salted passwords for customers’ user accounts.”

As a consequence, Salesforce said it’s resetting all Heroku user passwords and ensuring that potentially affected credentials are refreshed. It also emphasized that internal Heroku credentials were rotated and extra detections have been put in place.

The attack campaign, which GitHub discovered on April 12, related to an unidentified actor leveraging stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and Travis-CI, to download data from dozens of organizations, including NPM.

The timeline of events as shared by the cloud platform is as follows –

  • April 7, 2022 – Threat actor obtains access to a Heroku database and downloads stored customer OAuth access tokens used for GitHub integration.
  • April 8, 2022 – Attacker enumerates metadata about customer repositories using the stolen tokens.
  • April 9, 2022 – Attacker downloads a subset of Heroku private repositories from GitHub

GitHub, last week, characterized the attack as highly targeted, adding the adversary was “only listing organizations in order to identify accounts to selectively target for listing and downloading private repositories.”

Heroku has since revoked all the access tokens and removed support for deploying apps from GitHub through the Heroku Dashboard to ascertain that “the integration is secure before we re-enable this functionality.”





TheHackersNews/

cyber security news

Post navigation

Previous Post: Thousands of Borrowers’ Data Exposed from ENCollect Debt Collection Service
Next Post: NAFSTARS Announces a Successful Fund Raise of $1․7 Million – Press release Bitcoin News

Related Posts

  • Twitter’s New Owner Elon Musk Wants DMs to be End-to-End Encrypted like Signal cyber security news
  • Microsoft Azure Vulnerability Exposes PostgreSQL Databases to Other Customers cyber security news
  • QNAP Advises to Mitigate Remote Hacking Flaws Until Patches are Available cyber security news
  • Hackers Gain Fileless Persistence on Targeted SQL Servers Using a Built-in Utility cyber security news
  • Russian Conti Ransomware Gang Threatens to Overthrow New Costa Rican Government cyber security news
  • 5 Benefits of Detection-as-Code cyber security news

Archives

  • May 2022

Categories

  • bitcoin news
  • cyber security news

Recent Posts

  • How Ethereum Uniswap Reached A Milestone Of $1T In Trading Volume
  • Russian Court Recognizes Cryptocurrency as Means of Payment, Prosecutors See Precedent – Regulation Bitcoin News
  • Bitcoin, Ethereum Exchange Inflows Suggest Sell-Offs Are Far From Over
  • SOL, NEAR Fall Over 10% During Tuesday’s Session – Market Updates Bitcoin News
  • Popular PyPI Package ‘ctx’ and PHP Library ‘phpass’ Hijacked to Steal AWS Keys

Recent Comments

No comments to show.
  • Biggest Dollar Holding Among Wealthiest Ethereum Whales bitcoin news
  • Bitcoin Carnage Continues As BTC Disintegrates To $34K bitcoin news
  • Institutional Investors Exit Market As Crypto Declines, New Report Reveals bitcoin news
  • A Story of Incredible Belief….. How GAIMIN Gladiator’s Acquired Team Tickles! – Sponsored Bitcoin News bitcoin news
  • Top Diamond Producer De Beers Deploys Blockchain-Based Platform at Scale – Blockchain Bitcoin News bitcoin news
  • HUMAN Protocol Foundation Awards Grant to VeritaTrust to Build on-Chain Rewards for Reviews – Press release Bitcoin News bitcoin news
  • Bankoff Crypto Cards Suspended Amid High Volume of Russian Transactions – Finance Bitcoin News bitcoin news
  • Tron Moves to 1-Week High, as Thorchain’s RUNE Nears Lowest Level Since January 2021 – Market Updates Bitcoin News bitcoin news

Copyright © 2022 Cyber Security And Bitcoin Blockchain News.

Powered by PressBook News Dark theme