Earlier quoted context omitted.
If you click through to the GH Issues I linked to there are some pretty good data points as to what happened. I didn't feel the need to copypasta. But yes, publicly exposed jenkins and repos lead to the compromise, not an uncommon story unfortunately. Perimeter - I didn't see much evidence of one existing and I didn't go probing their networks to find out. Security tropes are real for a reason, you don't have to beli…
> They've leaked before and they'll keep on leaking. GitHub even made it harder for people to fork private repos to their own public accounts but it still happens Can you provide some actual instances of this happening? Genuinely curious, as my org is currently migrating from enterprise to cloud.
Here's a good one from reddit: https://www.reddit.com/r/github/comments/9odnvw/someone_fork...
Its also discussed reasonably well in the infosec community. Basically GitHub is a great place to find other people's passwords and API keys.