To get in touch about speaking at your event, email [email protected]

cje
press Apr 18, 2022 · SC Media

Threat actors that compromised two OAuth integrators could potentially penetrate cloud systems

SC Media reported on threat actors who compromised OAuth integrators and gained potential access to cloud systems through stolen tokens from Heroku and Travis-CI. Casey Ellis provided analysis on how the compromised credentials could be leveraged to breach private code repositories and emphasized the cascading risks across integrated development environments.

Source description — as published

Covers a security incident where stolen OAuth tokens from Heroku and Travis-CI were used to breach private code repositories hosted on GitHub.