logo

The Cloudflare source code breach: Lessons learned

ID: c5a14a49-06d0-5959-8d1c-2c943d292f39

STIX ID: report--c5a14a49-06d0-5959-8d1c-2c943d292f39

Feed Name: ReversingLabs Blog

Threat Score
75/100

Date Published: 2024-02-06

Date Updated: 2026-04-29

Author: [email protected] (Paul Roberts)

...
...

Cloudflare disclosed a November 2023 incident where attackers leveraged credentials leaked in an October Okta breach to pivot into Cloudflare's Atlassian environment and download 76 Bitbucket repositories; while Cloudflare reports no evidence of customer-data, network, or SSL key compromise, some repositories contained encrypted secrets that were immediately rotated and the company launched an internal 'Code Red' remediation to search for vulnerabilities and exposed secrets.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.