CircleCI: Rotate Stored Secrets ASAP

Share This Post

DevOps platform CircleCI is warning users of its continuous integration and deployment (CI/CD) to “immediately” rotate all secrets — think passwords, API keys, SSH keys, configuration files, OAuth tokens, etc. — stored on the platform in the wake of a security incident under investigation at the company.

In a blog post this week, Ron Zuber, CTO of CircleCI, urged customers to first rotate all secrets stored “in project environment variables or in contexts” and then check internal logs for signs of “unauthorized access” from Dec. 21, 2022, and up to the date of rotation.

“Additionally, if your project uses Project API tokens, we have invalidated those and you will need to replace them. You can find more information on how to do that in our documentation here,” Zuber said.

The company is continuing to investigate the security breach and plans to provide more details as they emerge. “At this point, we are confident that there are no unauthorized actors active in our systems; however, out of an abundance of caution, we want to ensure that all customers take certain preventative measures to protect your data as well,” Zuber wrote.

Meanwhile, CI/CD services have become a popular target of cryptominers for deploying code and setting up cloud-based mining platforms, a recent report from Sysdig found.

Read More

Dark Reading

More Articles

Article

Navigating SEC Regulations In Cybersecurity And Incident Response

Free video resource for cybersecurity professionals. As 2024 approaches, we all know how vital it is to keep up to date with regulatory changes that affect our work. We get it – it’s a lot to juggle, especially when you’re in the trenches working on an investigation, handling, and responding to incidents.

Article

BFU – Seeing is Believing

Oh no, the device is in BFU. This is the common reaction; a device needs extracting, and you find it in a BFU state. Often, there’s an assumption that a BFU extraction will only acquire basic information, but that isn’t always the case.