Grafana Labs Breach Exposes GitHub Repositories and Codebase
ID: 160161ce-5424-51e2-8ea8-556a81fd8e6a
STIX ID: report--160161ce-5424-51e2-8ea8-556a81fd8e6a
Feed Name: Cyber Press
Threat Score
A sophisticated attacker exploited a misconfigured GitHub Actions pull_request_target workflow at Grafana Labs by injecting a malicious curl in a forked repository, stealing a privileged token to download the company’s private codebase and demanding ransom; Grafana detected the breach via a triggered canary token, prevented further access, removed the vulnerable workflow, invalidated credentials, and reported no customer data was accessed.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
