Grafana Labs Security Breach – Hackers Access GitHub and Download Codebase
ID: 2927a242-4c9a-5c5a-ab3f-75fc39c5cbad
STIX ID: report--2927a242-4c9a-5c5a-ab3f-75fc39c5cbad
Feed Name: cybersecurityNews.com
Threat Score
Grafana Labs disclosed that an attacker leveraged a misconfigured GitHub Action triggered on pull_request_target to steal a privileged token, exfiltrate multiple private repositories (the company’s codebase), and attempt extortion; Grafana invalidated credentials, removed the vulnerable workflow, disabled public workflows, and reported no evidence of customer data or system impact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
