• Home
  • About us
  • Contact us
  • DMCA
Forbes.llc
  • Home
  • Innovation
    • 5G
    • AI
    • Big Data
    • Cloud
    • Cloud 100
    • Consumer Tech
    • COP26
    • Cybersecurity
    • Enterprise Tech
    • Future Of Work
    • Games
  • Leadership
    • Careers
    • CEO Network
    • CFO Network
    • CHRO Network
    • CIO Network
    • CMO Network
    • Money
      • ETFs & Mutual Funds
      • Fintech
      • Hedge Funds & Private Equity
      • Investing
      • Investing Basic
      • Markets
      • Personal Finance
      • Premium Investing Newsletters
  • Forbes Digital Assets
    • Dashboard
    • Traded Assets
    • Research
    • Events
    • Crypto Portfolios
  • Business
    • Aerospace & Defense
    • Energy
    • Food & Drink
    • Hollywood & Entertainment
    • Manufacturing
    • Media
    • Policy
  • Small Business
    • Small Business Strategy
    • Enterprise Tech
    • Franchises
  • Lifestyle
    • Arts
    • Boats & Planes
    • Cars & Bikes
    • Dining
    • Real Estate
      • Commercial Real Estate
      • Residential Real Estate
      • Forbes Global Properties
      • Vetted
No Result
View All Result
  • Home
  • Innovation
    • 5G
    • AI
    • Big Data
    • Cloud
    • Cloud 100
    • Consumer Tech
    • COP26
    • Cybersecurity
    • Enterprise Tech
    • Future Of Work
    • Games
  • Leadership
    • Careers
    • CEO Network
    • CFO Network
    • CHRO Network
    • CIO Network
    • CMO Network
    • Money
      • ETFs & Mutual Funds
      • Fintech
      • Hedge Funds & Private Equity
      • Investing
      • Investing Basic
      • Markets
      • Personal Finance
      • Premium Investing Newsletters
  • Forbes Digital Assets
    • Dashboard
    • Traded Assets
    • Research
    • Events
    • Crypto Portfolios
  • Business
    • Aerospace & Defense
    • Energy
    • Food & Drink
    • Hollywood & Entertainment
    • Manufacturing
    • Media
    • Policy
  • Small Business
    • Small Business Strategy
    • Enterprise Tech
    • Franchises
  • Lifestyle
    • Arts
    • Boats & Planes
    • Cars & Bikes
    • Dining
    • Real Estate
      • Commercial Real Estate
      • Residential Real Estate
      • Forbes Global Properties
      • Vetted
Social icon element need JNews Essential plugin to be activated.
No Result
View All Result
Forbes LLC
No Result
View All Result

Hackers steal GitHub Desktop and Atom code-signing certificates

by
January 31, 2023

[ad_1]

January 31, 2023Rabbi Lakshmanansecurity incident / encryption

GitHub revealed Monday that an unknown attacker has stolen encrypted code-signing certificates associated with some versions of GitHub Desktop for Mac and the Atom app.

As a result, the company is taking steps to revoke published certificates out of an abundance of caution. The following versions of GitHub Desktop for Mac have been disabled: 3.0.2, 3.0.3, 3.0.4, 3.0.5, 3.0.6, 3.0.7, 3.0.8, 3.1.0, 3.1.1 , and 3.1.2.

Atom versions 1.63.0 and 1.63.1 of 1.63.0 are also scheduled to stop working on February 2, 2023, requiring users to downgrade to the previous version of Atom (1.60.0) . GitHub Desktop for Windows is not affected.

A Microsoft-owned subsidiary said on December 7, 2022, it detected unauthorized access to a series of deprecated repositories used to plan and develop GitHub Desktop and Atom.

The repository was allegedly cloned the day before by a compromised Personal Access Token (PAT) tied to the machine account. None of the repositories contained customer data and the compromised credentials were subsequently revoked. GitHub has not disclosed how the token was compromised.

“Several cryptographic code-signing certificates were stored in these repositories and used via actions in the GitHub Desktop and Atom release workflows,” said Alexis Wales of GitHub. “There is no evidence that an attacker was able to decrypt or use these certificates.”

Note that if the certificates are successfully decrypted, an adversary could use those certificates to sign a trojanized application, disguising it as originating from GitHub.

The three compromised certificates (two Digicert code signing certificates and one Apple Developer ID certificate used for Windows) are scheduled to expire on February 2, 2023.

The code hosting platform also said it released a new version of its desktop app on January 4, 2023. It is signed with a new certificate that has not been published to the attacker. Additionally, they emphasized that no unauthorized changes were made to the code in these repositories.

Did you find this article interesting?Please follow us twitter ○ and LinkedIn to read more exclusive content we post.



[ad_2]

Source link

Next Post
iQOO 11 5G Review: Does It End Your Quest for the Ultimate Smartphone?

iQOO 11 5G Review: Does It End Your Quest for the Ultimate Smartphone?

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent Posts

  • Pet Insurance That Covers Pre-Existing Conditions – Forbes Advisor
  • Pet Insurance That Covers Pre-Existing Conditions – Forbes Advisor
  • Pros and Cons – Forbes Advisor
  • Home
  • About us
  • Contact us
  • DMCA

© 2022 forbes - Copyrights reserved by Forbes LLC.

No Result
View All Result
  • Home
  • Review
  • Apple
  • Applications
  • Computers
  • Gaming
  • Gear
    • Audio
    • Camera
    • Smartphone
  • Microsoft
  • Photography
  • Security

© 2022 forbes - Copyrights reserved by Forbes LLC.