GitLab attacks put development secrets and supply chains at risk
Daily Cyber News: GitLab attacks put development secrets and supply chains at risk
Development secrets and downstream systems are exposed as attackers exploit a maximum-severity issue in self-managed GitLab. Under certain conditions, an unauthenticated request can read arbitrary files from affected Community and Enterprise Edition servers. Observed activity progressed from initial probing to the theft of configuration files and S S H settings that may contain credentials and CI/CD secrets.
For more cybersecurity news and the full Daily Cyber newsletter, visit DailyCyber.News.
Cybersecurity training, courses, books, and resources: BareMetalCyber.com.
Topics: cybersecurity news, cybersecurity, cyber risk, supply chain, GitLab, attacks, development, secrets, supply, chains.