The Cloudflare source code breach: Lessons learned
ID: c5a14a49-06d0-5959-8d1c-2c943d292f39
STIX ID: report--c5a14a49-06d0-5959-8d1c-2c943d292f39
Feed Name: ReversingLabs Blog
Threat Score
Cloudflare disclosed a November 2023 incident where attackers leveraged credentials leaked in an October Okta breach to pivot into Cloudflare's Atlassian environment and download 76 Bitbucket repositories; while Cloudflare reports no evidence of customer-data, network, or SSL key compromise, some repositories contained encrypted secrets that were immediately rotated and the company launched an internal 'Code Red' remediation to search for vulnerabilities and exposed secrets.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
