Home / Companies / Arnica / Blog / August 2022

August 2022 Summaries

2 posts from Arnica

Filter
Month: Year:
Post Summaries Back to Blog
LastPass recently notified users of a security incident in its developer environment, which led to partial disclosure of its source code and other proprietary technical details. The company has asserted that customer data was not affected by the breach. While it's unclear how the hackers gained access, this incident highlights the importance of securing development environments as an under-appreciated attack surface.
Aug 26, 2022 785 words in the original blog post.
A security researcher known as pl0x claimed responsibility for cloning thousands of GitHub repositories and inserting backdoors into the code, which sent environment variables to a Russian virtual private server and ran code from that server. The cloned repositories were all just clones of real repositories, and no real accounts were compromised. pl0x claimed to be pursuing a bug bounty, but has not yet provided any report or evidence to support this claim. GitHub's handling of the situation prevented further analysis of the threat, as they quickly removed the affected repositories. The incident highlights the importance of proper security practices and raises questions about the potential misuse of GitHub cloning features for malicious purposes.
Aug 17, 2022 1,325 words in the original blog post.