CI/CD service CircleCI says hackers infected an employee's laptop and used 2FA credentials to breach the company's systems and steal its data in December 2022
CircleCI's chief technology officer said malicious hackers infected one of their engineer's laptops and stole elevated account privileges …
SC Media Derek B. Johnson
Related Coverage
- CircleCI's hack caused by malware stealing engineer's 2FA-backed session BleepingComputer · Lawrence Abrams
- CircleCI says hackers stole encryption keys and customers' secrets TechCrunch · Zack Whittaker
- CircleCI incident report for January 4, 2023 security incident CircleCI · Rob Zuber
- Malware Attack on CircleCI Engineer's Laptop Leads to Recent Security Incident The Hacker News
- CircleCI probe links malware placed on engineer's laptop to larger breach Cybersecurity Dive
Discussion
-
@robhartsock
Rob Hartsock
on x
Everyone, literally everyone here at @CircleCI has done an outstanding job working to resolve this incident. Couldn't be more proud to be part of this team! https://twitter.com/...
-
@lorenc_dan
Dan Lorenc
on x
Really good breakdown and transparency into the incident by @CircleCI: https://circleci.com/...
-
@dyn___
Aaron Grattafiori
on x
https://circleci.com/... “we have learned that an unauthorized third party leveraged malware deployed to a CircleCI engineer's laptop in order to steal a valid, 2FA-backed SSO session...” Common 2FA bypass technique by access brokers and other attackers... Design appropriately.
-
@arekfurt
@arekfurt
on x
I sincerely commend CircleCI for being more open about their breach than entities typically are. Unfortunately, that openness shows their security posture re. privileged access to production stunk and their security people misunderstand the issues there. https://circleci.com/...
-
@arekfurt
@arekfurt
on x
The CircleCI thing is yet another case where an attacker got malware onto a user's machine (in this case a privileged user with access to production infrastructure), stole browser session cookies, was thus able to impersonate the user without using MFA, and caused big problems.
-
@magoo
Ryan McGeehan
on x
CircleCI breach retrospective w/ IOCs and TTPs Quick TLDR: 1. Malware on eng laptop 2. Stole active SSO session for a remote session 4. Generated production access tokens 5. Exfil'd customer ENVs, tokens, keys. 6. CircleCI encryption keys exfil'd too. https://circleci.com/...
-
@prahathess
@prahathess
on x
A good read and example on incident disclosure https://circleci.com/... Key takeaways: - Assume Dev PC's are compromised and treat them as such - Transparent and Detailed Incident disclosure goes a long way in building trust
-
@circleci
@circleci
on x
Incident Report | #CircleCI Security Alert [4 Jan. 2023] What happened, what we've learned and what our plans are to continuously improve our security posture for the future. Full report: https://circleci.com/... https://twitter.com/...