Red Hat confirms security incident after hackers claim GitHub breach
ID: da078db8-44ab-52b6-b891-d1c1c0c966a9
STIX ID: report--da078db8-44ab-52b6-b891-d1c1c0c966a9
Feed Name: Bleeping Computer
Red Hat confirmed unauthorized access to a self-managed GitLab instance used by its Consulting division after an extortion group calling itself the Crimson Collective claimed to have stolen ~570GB from ~28,000 repositories, including Customer Engagement Reports that may contain sensitive infrastructure details and authentication tokens. The attackers posted directory listings and a CER index naming many high-profile organizations; Red Hat says the issue was isolated to the Consulting GitLab instance, removed unauthorized access, implemented hardening, and is notifying affected customers while investigations continue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
