Docker Hub Hacked – 190k accounts, GitHub tokens revoked, Builds disabled
492 by lugg | 93 comments on Hacker News.
Received this email a few minutes ago: "On Thursday, April 25th, 2019, we discovered unauthorized access to a single Hub database storing a subset of non-financial user data. Upon discovery, we acted quickly to intervene and secure the site. We want to update you on what we've learned from our ongoing investigation, including which Hub accounts are impacted, and what actions users should take. Here is what we’ve learned: During a brief period of unauthorized access to a Docker Hub database, sensitive data from approximately 190,000 accounts may have been exposed (less than 5% of Hub users). Data includes usernames and hashed passwords for a small percentage of these users, as well as Github and Bitbucket tokens for Docker autobuilds. Actions to Take: - We are asking users to change their password on Docker Hub and any other accounts that shared this password. - For users with autobuilds that may have been impacted, we have revoked GitHub tokens and access keys, and ask that you reconnect to your repositories and check security logs to see if any unexpected actions have taken place. - You may view security actions on your GitHub or BitBucket accounts to see if any unexpected access has occurred over the past 24 hours -see http://bit.ly/2V1kwFO and http://bit.ly/2GCGt43 - This may affect your ongoing builds from our Automated build service. You may need to unlink and then relink your Github and Bitbucket source provider as described in https://dockr.ly/2UXNvKQ We are enhancing our overall security processes and reviewing our policies. Additional monitoring tools are now in place. Our investigation is still ongoing, and we will share more information as it becomes available. Thank you, Kent Lamb Director of Docker Support info@docker.com"
//
New best story on Hacker News: Docker Hub Hacked – 190k accounts, GitHub tokens revoked, Builds disabled
April 27, 2019 / by Huzaifa / in Hacker News, latest news / with No comments /
Related Posts:
New best story on Hacker News: Apple blocks Facebook from running its internal iOS appsApple blocks Facebook from running its internal iOS apps 703 by epaga | 292 comments on Hacker News. // … Read More
New best story on Hacker News: Google’s also peddling a data collector through Apple’s back doorGoogle’s also peddling a data collector through Apple’s back door 523 by minimaxir | 218 comments on Hacker News. // … Read More
New best story on Hacker News: Ending our Medium integrationEnding our Medium integration 868 by thebaer | 346 comments on Hacker News. // … Read More
New best story on Hacker News: Why isn't the internet more fun and weird?Why isn't the internet more fun and weird? 1033 by firloop | 433 comments on Hacker News. // … Read More
New best story on Hacker News: Remembering Roger Boisjoly: He Tried to Stop Shuttle Challenger LaunchRemembering Roger Boisjoly: He Tried to Stop Shuttle Challenger Launch 533 by drewvolpe | 163 comments on Hacker News. // … Read More
0 comments:
Post a Comment