Supply chain security incident at CircleCI: Rotate your secrets
Blog post from Snyk
CircleCI disclosed a security incident on January 4 after evidence of a possible account intrusion emerged through an AWS CanaryToken alert, prompting the company to advise all customers to rotate secrets stored in project environment variables and contexts and review logs for suspicious access during the affected period. CircleCI also invalidated personal and project API tokens and rotated GitHub and Bitbucket OAuth tokens, while users were encouraged to inventory credentials, revoke rather than delete secrets, and rotate environment variables and SSH keys despite the potential disruption to CI/CD operations. The incident highlights risks posed by secret sprawl and long-lived static credentials, which can be difficult to track, may persist after services are retired, and can enable broader software supply-chain compromises if exposed. Recommended safeguards include encrypted secrets-management vaults, policy-controlled developer access, automated and regular rotation procedures, and dynamic short-lived credentials based on zero standing privileges, which limit permissions and reduce the usefulness of compromised keys.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 35 | 681 | 84 | 53 | +116% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.