Slow Fog: The Open Source data visualization tool Grafana is suspected to have been attacked by hackers, and the attacker may have implanted malicious code.

robot
Abstract generation in progress

According to Deep Tide TechFlow news on April 27, the Chief Information Security Officer 23pds (@im23pds) of SlowMist security team disclosed that the Open Source data visualization tool Grafana was suspected to have been hacked. The attacker used Gato-X to steal the Secret Key and attacked multiple code repositories using application tokens.

It is reported that attackers may inject JavaScript code and steal sensitive information by constructing malicious branch names. Potential targets of the attackers include: generating high-privilege GitHub tokens using tibdex/github-app-token, manipulating the grafana/grafana code repository (including code, branches, and release workflows), as well as implanting hidden backdoors or tampering with future release packages.

View Original
The content is for reference only, not a solicitation or offer. No investment, tax, or legal advice provided. See Disclaimer for more risks disclosure.
  • Reward
  • Comment
  • Share
Comment
0/400
No comments