Grafana Labs internal source code accessed
twitter.com
Grafana Labs internal source code accessed
1–10 of 28 posts
Re: Grafana Labs internal source code accessed
#2Their whole repo had been made public !!!!
https://github.com/grafana/grafana
/s
Re: Grafana Labs internal source code accessed
#3aren't they just psql tho? well, i guess we will find out soon.
Re: Grafana Labs internal source code accessed
#4Quote: “ The attacker attempted to blackmail us, demanding payment to prevent the release of our codebase. ...we’ve determined the appropriate path forward is to not pay the ransom.”
Re: Grafana Labs internal source code accessed
#5Their whole repo had been made public !!!! https://github.com/grafana/grafana /s
This is worse than the Linux kernel source code leaks of April 1st.
Re: Grafana Labs internal source code accessed
#6non-twitter link https://xcancel.com/grafana/status/2055827123236171827#m
Re: Grafana Labs internal source code accessed
#7>We recently discovered that an unauthorized party obtained a token with access to the Grafana Labs GitHub environment, enabling the threat actor to download our codebase.
I don't much like the securityese dialect of bureaucratese, but doesn't it make more sense as "We recently discovered that a threat actor obtained a token with access to the Grafana Labs GitHub environment, enabling the unauthorized party to download our codebase" ?
you can't just drop in buzzwords willy nilly, they buzz better in the right places.
Re: Grafana Labs internal source code accessed
#8Quote: “ The attacker attempted to blackmail us, demanding payment to prevent the release of our codebase. ...we’ve determined the appropriate path forward is to not pay the ransom.”
Don't pay the Dane-geld: https://en.wikipedia.org/wiki/Dane-geld_(poem)
Re: Grafana Labs internal source code accessed
#9Their whole repo had been made public !!!! https://github.com/grafana/grafana /s
I think they mean grafana cloud.
Re: Grafana Labs internal source code accessed
#10I wonder if this is related to the supply chain attack they talked about at GrafanaCon[1] or a fresh leak. If latter, wonder what they missed since it seemed like they got their detectors/scanners set up well. Curious to read the report on this.