Customize Consent Preferences

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorized as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ... 

Always Active

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

No cookies to display.

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

No cookies to display.

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

No cookies to display.

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

No cookies to display.

Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.

No cookies to display.

admin
Pinned May 2, 2021

<> Embed

@  Email

Report

Uploaded by user
US investigates code testing hack that could affect thousands of companies
<> Embed @  Email Report

US investigates code testing hack that could affect thousands of companies

US investigates code testing hack that could affect thousands of companies

Codecov’s customers include tech and pharmaceutical giants.

Jon Fingas
J. Fingas
April 18th, 2021
US investigates code testing hack that could affect thousands of companies | DeviceDaily.com
Andrew Brookes via Getty Images

A recent breach has prompted fears of another SolarWinds-style hack that could have ramifications for numerous large companies. Reuters reports that federal officials are investigating a hack at Codecov, a code testing firm with 29,000 customers that include Proctor & Gamble, the Washington Post and tech companies like Atlassian and GoDaddy. The intrusion appears to have lasted for months, putting clients at risk.

Codecov said that attackers exploited a flaw in a Docker image creation process to make “periodic, unauthorized” changes to the company’s Bash Uploader script starting on January 31st. The modifications gave the hackers power to export customer info and send it to an outside server. However, Codecov only learned of the incident on April 1st. The team refreshed its internal sign-ins, set up auditing and monitoring systems and had the hosting provider shut down the server, but it wasn’t certain how many customers had been affected.

A spokesperson for Codecov declined to comment on the incident beyond the statement confirming federal involvement. Atlassian said it hadn’t seen evidence it was affected, but Procter & Gamble and other companies hadn’t initially responded to Reuters requests for comment.

The concern, as you might imagine, is that the perpetrators might have obtained sensitive data from Codecov’s customers without giving them a chance to respond or notify their own users. It could be a minor incident if the attackers didn’t use the flaw, but it could also represent a crisis if there were any successful thefts.

All products recommended by Engadget are selected by our editorial team, independent of our parent company. Some of our stories include affiliate links. If you buy something through one of these links, we may earn an affiliate commission.

Engadget

(22)