• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
dropbox breach: hackers unauthorizedly accessed 130 github source code repositories

Dropbox Breach: Hackers Unauthorizedly Accessed 130 GitHub Source Code Repositories

You are here: Home / General Cyber Security News / Dropbox Breach: Hackers Unauthorizedly Accessed 130 GitHub Source Code Repositories
November 2, 2022

File hosting support Dropbox on Tuesday disclosed that it was the victim of a phishing campaign that permitted unknown danger actors to achieve unauthorized obtain to 130 of its supply code repositories on GitHub.

“These repositories included our have copies of 3rd-party libraries slightly modified for use by Dropbox, internal prototypes, and some tools and configuration information employed by the security staff,” the business disclosed in an advisory.

The breach resulted in the accessibility of some API keys utilised by Dropbox builders as perfectly as “a couple of thousand names and email addresses belonging to Dropbox workforce, recent and past prospects, gross sales sales opportunities, and distributors.”

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


It, even so, stressed that the repositories did not incorporate source code related to its main apps or infrastructure.

Dropbox, which presents cloud storage, knowledge backup, and doc signing expert services, amongst some others, has around 17.37 million having to pay buyers and 700 million registered users as of August 2022.

The disclosure will come extra than a month immediately after the two GitHub and CircleCI warned of phishing attacks developed to steal GitHub credentials through bogus notifications purporting to be from the CI/CD system.

The San Francisco-based mostly company noted that “numerous Dropboxers gained phishing e-mails impersonating CircleCI” in early Oct, some of which slipped via its automatic spam filters to land in employees’ email inboxes.

“These genuine-seeking email messages directed staff to stop by a faux CircleCI login page, enter their GitHub username and password, and then use their hardware authentication essential to move a Just one Time Password (OTP) to the malicious web page,” Dropbox explained.

CyberSecurity

The enterprise did not expose how a lot of of its employees fell for the phishing attack, but reported it took prompt motion to rotate all exposed developer qualifications and that it alerted law enforcement authorities.

It also stated it observed no evidence that any buyer details was stolen as a result of the incident, introducing it can be upgrading its two-factor authentication programs to guidance components security keys for phishing resistance.

“vigilant pros can drop prey to a cautiously crafted information sent in the right way at the appropriate time,” the enterprise concluded. “This is precisely why phishing continues to be so successful.”

Located this short article attention-grabbing? Comply with THN on Fb, Twitter  and LinkedIn to study a lot more exceptional written content we write-up.


Some pieces of this article are sourced from:
thehackernews.com

Previous Post: «openssl 3.0 vulnerability: patch released for security scare OpenSSL 3.0 vulnerability: Patch released for security scare
Next Post: A Third of Security Leaders Considering Quitting Their Current Role Cyber Security News»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Zero-Click Agentic Browser Attack Can Delete Entire Google Drive Using Crafted Emails
  • Critical XXE Bug CVE-2025-66516 (CVSS 10.0) Hits Apache Tika, Requires Urgent Patch
  • Chinese Hackers Have Started Exploiting the Newly Disclosed React2Shell Vulnerability
  • Intellexa Leaks Reveal Zero-Days and Ads-Based Vector for Predator Spyware Delivery
  • “Getting to Yes”: An Anti-Sales Guide for MSPs
  • CISA Reports PRC Hackers Using BRICKSTORM for Long-Term Access in U.S. Systems
  • JPCERT Confirms Active Command Injection Attacks on Array AG Gateways
  • Silver Fox Uses Fake Microsoft Teams Installer to Spread ValleyRAT Malware in China
  • ThreatsDay Bulletin: Wi-Fi Hack, npm Worm, DeFi Theft, Phishing Blasts— and 15 More Stories
  • 5 Threats That Reshaped Web Security This Year [2025]

Copyright © TheCyberSecurity.News, All Rights Reserved.