Mintlify says customer GitHub tokens exposed in data breach

Date:

Share post:


Documentation startup Mintlify says dozens of customers had GitHub tokens exposed in a data breach at the start of the month and publicly disclosed last week.

Mintlify helps developers create documentation for their software and source code by requesting access and tapping directly into the customer’s GitHub source code repositories. Mintlify counts fintech, database and AI startups as customers.

In a blog post Monday, Mintlify blamed its March 1 incident on a vulnerability in its own systems, but said 91 of its customers had their GitHub tokens compromised as a result.

These private tokens allow GitHub users to share their account access with third parties apps, including companies like Mintlify. If these tokens are stolen, an attacker could obtain the same level of access to a person’s source code as the token permits.

“The users have been notified, and we’re working with GitHub to identify whether the tokens were used to access private repositories,” Mintlify co-founder Han Wang wrote in a blog post.

News of the incident became public last week when some users on Reddit and Hacker News commented after getting an email from Mintlify on Friday about the incident, days after the company’s blog post initially told customers that “no further action is required on your part.”

In a post discussing the breach on Hacker News, Wang said a vulnerability in its systems was leaking the company’s internal admin credentials to customers. Those credentials could then be used to access the company’s internal endpoints to access other unspecified sensitive user information, Wang said.

Wang said that the company was in the process of deprecating the use of private tokens “to prevent an incident like this from ever happening again.”

While the blog post describes the person who discovered the vulnerability as a bug bounty reporter, the company’s co-founder Wang described the events as malicious.

“The targets of this attack were GitHub tokens of our users,” Wang told TechCrunch by email.

“Investigations with one impacted customer revealed that the leaked token was likely not used by the attacker. We are currently working with GitHub and our customers to uncover if any of the other tokens were used by the attacker,” Wang said.



Source link

Lisa Holden
Lisa Holden
Lisa Holden is a news writer for LinkDaddy News. She writes health, sport, tech, and more. Some of her favorite topics include the latest trends in fitness and wellness, the best ways to use technology to improve your life, and the latest developments in medical research.

Recent posts

Related articles

a16z’s American Dynamism team launches program to introduce technical minds to VC

Andreessen Horowitz’s American Dynamism fund has established a new fellowship program aimed at introducing top engineers and...

Microsoft’s new ‘Volumetric Apps’ for Quest headsets extend Windows apps into the 3D space

Microsoft announced on Tuesday during its annual Build conference that it’s bringing “Windows Volumetric Apps” to Meta...

The ‘vote Trump’ spam that hit Bluesky in May came from decentralized rival Nostr

Decentralized social networks aren’t immune to botnet-driven spam, as a recent spam attack on Bluesky demonstrates. Earlier...

There’s a real appetite for a fintech alternative to QuickBooks

Welcome to TechCrunch Fintech! This week, we’re looking at the continued fallout from Synapse’s bankruptcy, how Layer...

Bill Gates-backed wind startup AirLoom is raising $12M, filings reveal

It started with a drawing on a napkin. Now, AirLoom Energy is raising $12.7 million in fresh...

As a U.S. ban looms, TikTok announces a $1M program for socially driven creators

TikTok is pulling out all the stops to prevent its impending ban in the United States. Aside...

Stack AI wants to make it easier to build AI-fueled workflows

Stack AI’s co-founders, Antoni Rosinol and Bernardo Aceituno, were PhD students at MIT wrapping up their degrees...

Senate study proposes ‘at least’ $32B yearly for AI programs

A long-running working group in the Senate has issued its policy recommendation for federal funding for AI:...