Close Menu
Beverly Hills Examiner

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Ruta Lee Guests On “If These Walls Could Talk” With Hosts Wendy Stuart and Tym Moss Wednesday, September 2nd, 2026

    August 28, 2026

    Hormuz is Dead By Howard Bloom

    August 28, 2026

    Royal Blood pack out The Gallery tent for raucous Reading 2026 “surprise” set

    August 28, 2026
    Facebook X (Twitter) Instagram
    Beverly Hills Examiner
    • Home
    • US News
    • Politics
    • Business
    • Science
    • Technology
    • Lifestyle
    • Music
    • Television
    • Film
    • Books
    • Contact
      • About
      • Amazon Disclaimer
      • DMCA / Copyrights Disclaimer
      • Terms and Conditions
      • Privacy Policy
    Beverly Hills Examiner
    Home»Technology»CircleCI says hackers stole encryption keys and customers’ secrets • TechCrunch
    Technology

    CircleCI says hackers stole encryption keys and customers’ secrets • TechCrunch

    By AdminJanuary 15, 2023
    Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    CircleCI says hackers stole encryption keys and customers’ secrets • TechCrunch


    CircleCi, a software company whose products are popular with developers and software engineers, confirmed that some customers’ data was stolen in a data breach last month.

    The company said in a detailed blog post on Friday that it identified the intruder’s initial point of access as an employee’s laptop that was compromised with malware, allowing the theft of session tokens used to keep the employee logged in to certain applications, even though their access was protected with two-factor authentication.

    The company took the blame for the compromise, calling it a “systems failure,” adding that its antivirus software failed to detect the token-stealing malware on the employee’s laptop.

    Session tokens allow a user to stay logged in without having to keep re-entering their password or re-authorizing using two-factor authentication each time. But a stolen session token allows an intruder to gain the same access as the account holder without needing their password or two-factor code. As such, it can be difficult to differentiate between a session token of the account owner, or a hacker who stole the token.

    CircleCi said the theft of the session token allowed the cybercriminals to impersonate the employee and gain access to some of the company’s production systems, which store customer data.

    “Because the targeted employee had privileges to generate production access tokens as part of the employee’s regular duties, the unauthorized third party was able to access and exfiltrate data from a subset of databases and stores, including customer environment variables, tokens, and keys,” said Rob Zuber, the company’s chief technology officer. Zuber said the intruders had access from December 16 through January 4.

    Zuber said that while customer data was encrypted, the cybercriminals also obtained the encryption keys able to decrypt customer data. “We encourage customers who have yet to take action to do so in order to prevent unauthorized access to third-party systems and stores,” Zuber added.

    Several customers have already informed CircleCi of unauthorized access to their systems, Zuber said.

    The post-mortem comes days after the company warned customers to rotate “any and all secrets” stored in its platform, fearing that hackers had stolen its customers’ code and other sensitive secrets used for access to other applications and services.

    Zuber said that CircleCi employees who retain access to production systems “have added additional step-up authentication steps and controls,” which should prevent a repeat-incident, likely by way of using hardware security keys.

    The initial point of access — the token-stealing on an employee’s laptop — bears some resemblance to how the password manager giant LastPass was hacked, which also involved an intruder targeting an employee’s device, though it’s not known if the two incidents are linked. LastPass confirmed in December that its customers’ encrypted password vaults were stolen in an earlier breach. LastPass said the intruders had initially compromised an employee’s device and account access, allowing them to break into LastPass’ internal developer environment.

    Updated headline to better reflect the customer data that was taken.



    Original Source Link

    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Email Reddit Telegram
    Previous ArticleGene Drives Could Fight Malaria and Other Global Killers but Might Have Unintended Consequences
    Next Article The Long Arc of Long Covid – The Assignment with Audie Cornish

    RELATED POSTS

    Apple TV is raising its subscription prices again

    August 28, 2026

    A Judge Has Blocked the Pentagon’s Attempt to Blacklist Anthropic

    August 28, 2026

    This former PG&E engineer is building a ‘Google Maps for the underground’

    August 27, 2026

    How to See the Partial Lunar Eclipse and Blood Moon on August 27

    August 27, 2026

    Ex-Meta scientists want to bring visual AI to the factory floor

    August 26, 2026

    ‘Darth Vader’ Wants You to Know He Definitely Supports Flock Surveillance

    August 26, 2026
    latest posts

    Ruta Lee Guests On “If These Walls Could Talk” With Hosts Wendy Stuart and Tym Moss Wednesday, September 2nd, 2026

    Who else but hosts Wendy Stuart and Tym Moss could “spill the tea” on their weekly…

    Hormuz is Dead By Howard Bloom

    August 28, 2026

    Royal Blood pack out The Gallery tent for raucous Reading 2026 “surprise” set

    August 28, 2026

    Billionaire Panda Express co-CEO says he never got burned out—even after working 12-hour days

    August 28, 2026

    A Nearly Crying Mike Johnson Warns That Democrats Will Investigate The Trump Family

    August 28, 2026

    Taylor Sheridan’s Landman faces lengthy wait as season 3 production timeline revealed

    August 28, 2026

    Apple TV is raising its subscription prices again

    August 28, 2026
    Categories
    • Books (1,453)
    • Business (6,357)
    • Cover Story (10)
    • Film (6,294)
    • Lifestyle (4,352)
    • Music (6,367)
    • Politics (6,341)
    • Science (5,705)
    • Technology (6,291)
    • Television (5,990)
    • Uncategorized (3)
    • US News (6,342)
    popular posts

    GoFundMe Launched for Hüsker Dü’s Greg Norton Following Cancer Diagnosis

    A GoFundMe page has been set up to help Hüsker Dü and UltraBomb bassist Greg…

    99¢ Paramount+, Starz and Showtime Among Prime Day Streaming Deals

    July 10, 2022

    Gina Zollman In Concert – Trinity Chamber Series – September 8th, 2024 Point Roberts, WA

    August 24, 2024

    What to Consider When Choosing an Internet Provider for Speed and Reliability

    March 14, 2026
    Archives
    Browse By Category
    • Books (1,453)
    • Business (6,357)
    • Cover Story (10)
    • Film (6,294)
    • Lifestyle (4,352)
    • Music (6,367)
    • Politics (6,341)
    • Science (5,705)
    • Technology (6,291)
    • Television (5,990)
    • Uncategorized (3)
    • US News (6,342)
    About Us

    We are a creativity led international team with a digital soul. Our work is a custom built by the storytellers and strategists with a flair for exploiting the latest advancements in media and technology.

    Most of all, we stand behind our ideas and believe in creativity as the most powerful force in business.

    What makes us Different

    We care. We collaborate. We do great work. And we do it with a smile, because we’re pretty damn excited to do what we do. If you would like details on what else we can do visit out Contact page.

    Our Picks

    Taylor Sheridan’s Landman faces lengthy wait as season 3 production timeline revealed

    August 28, 2026

    Apple TV is raising its subscription prices again

    August 28, 2026

    There Are So Many Conspiracy Theories About Dolly Parton and Vaccines

    August 28, 2026
    © 2026 Beverly Hills Examiner. All rights reserved. All articles, images, product names, logos, and brands are property of their respective owners. All company, product and service names used in this website are for identification purposes only. Use of these names, logos, and brands does not imply endorsement unless specified. By using this site, you agree to the Terms & Conditions and Privacy Policy.

    Type above and press Enter to search. Press Esc to cancel.

    We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept All”, you consent to the use of ALL the cookies. However, you may visit "Cookie Settings" to provide a controlled consent.
    Cookie SettingsAccept All
    Manage consent

    Privacy Overview

    This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
    Necessary
    Always Enabled
    Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
    CookieDurationDescription
    cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
    cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
    cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
    cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
    cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
    viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
    Functional
    Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
    Performance
    Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
    Analytics
    Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
    Advertisement
    Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
    Others
    Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
    SAVE & ACCEPT