Analytics service Waydev says hackers breached it earlier this month and stole GitHub, GitLab OAuth tokens, likely pivoting to attack other companies like Dave
NEW: Git analytics firm Waydev says hackers stole GitHub and GitLab OAuth tokens from its internal database earlier this month OAuth tokens have been used in at least 2 places, to breach https://dave.com/ and https://flood.io/ https://www.zdnet.com/... https://twitter.com/...
Something that caught my eye in Waydev's response is that they shared the hackers' IOCs, something that's rarely done these days. Can't publicly share who the hackers are, but I guess people can put things together on their own https://changelog.waydev.co/ ... https://twitter.com…
New breach: Digital banking app “Dave” was breached last month with 7.5M rows (3M email addresses) exposed and publicly shared. Also impacted were physical addresses, encrypted SSNs and bcrypt password hashes. 77% were already in @haveibeenpwned. More: https://www.zdnet.com/...
This breach shows you have to be *extra* picky with the 3rd party services you choose The build vs buy conversations you have in the early days of building a company need to include growth and long term risk; don't only focus on short term benefits https://www.zdnet.com/...