Suivre

Tens of thousands of user tokens are exposed via the Travis CI API, which allows anyone to access historical clear-text logs.

More than 770 million logs of free tier users are available, from which you can easily extract tokens, secrets, and other credentials associated with popular cloud service providers such as GitHub, AWS, and Docker Hub. Attackers can use this sensitive data to launch massive cyberattacks and to move laterally in the cloud.

blog.aquasec.com/travis-ci-sec

Inscrivez-vous pour prendre part à la conversation
nanao

Comme le soleil, les machines ne se couchent jamais.