Cyber Attacks

GitHub revokes signing certificates stolen in cyber attack

0

GitHub confirmed that hackers have stolen three digital certificates used for its Desktop and Atom applications during a cyber-attack in December 2022.

The company stated in a blog post that after investigating the accident, it concluded there was no risk to GitHub.com services and no unauthorized changes to the projects.

According to the post by Alexis Wales, GitHub’s vice president of security operations, a set of encrypted code signing certificates were exfiltrated. However, the certificates were password-protected, and they have no evidence of malicious use.

As a preventative measure, the Microsoft-owned company will revoke the exposed certificates used for the GitHub Desktop and Atom applications. Revoking these certificates will invalidate some versions of GitHub Desktop for Mac and Atom.

Several versions of GitHub Desktop for Mac between 3.0.2 and 3.1.2 will stop working on February 02, while GitHub Desktop for Windows will not be affected. As for the Atom text editor, versions 1.63.0 and 1.63.1 will stop working.

To continue using the software solutions, GitHub urged Mac users to upgrade the GitHub Desktop version to the latest release. Atom users must download a previous program version to keep working on it.

Wales recommends that users must take action on the above recommendations to continue using GitHub Desktop and Atom.

According to Kevin Bocek, VP of security strategy and threat intelligence at Venafi, revoking the certificates is a sensible move, as threat actors may use them to masquerade their software as coming from GitHub.

The GitHub disclosure comes weeks after the company introduced a new feature to set up automatic code scanning on repositories.

Priyanka R
Cyber Security Enthusiast, Security Blogger, Technical Editor, Author at Cyber Safe News

IceBreaker malware used to breach gaming companies

Previous article

Pro-Russian hackers hit Dutch and European hospitals

Next article

You may also like

Comments

Leave a reply

Your email address will not be published. Required fields are marked *