MacMusic  |  PcMusic  |  440 Software  |  440 Forums  |  440TV  |  Zicos
certificates
Search

GitHub Says Hackers Cloned Code-Signing Certificates in Breached Repository

Tuesday January 31, 2023. 04:22 PM , from Slashdot
GitHub said unknown intruders gained unauthorized access to some of its code repositories and stole code-signing certificates for two of its desktop applications: Desktop and Atom. From a report: Code-signing certificates place a cryptographic stamp on code to verify it was developed by the listed organization, which in this case is GitHub. If decrypted, the certificates could allow an attacker to sign unofficial versions of the apps that had been maliciously tampered with and pass them off as legitimate updates from GitHub. Current versions of Desktop and Atom are unaffected by the credential theft.

'A set of encrypted code signing certificates were exfiltrated; however, the certificates were password-protected and we have no evidence of malicious use,' the company wrote in an advisory. 'As a preventative measure, we will revoke the exposed certificates used for the GitHub Desktop and Atom applications.' The revocations, which will be effective on Thursday, will cause certain versions of the apps to stop working.

Read more of this story at Slashdot.
https://tech.slashdot.org/story/23/01/31/1416239/github-says-hackers-cloned-code-signing-certificate...
News copyright owned by their original publishers | Copyright © 2004 - 2024 Zicos / 440Network
Current Date
Apr, Thu 25 - 04:13 CEST