1. https://appdevelopermagazine.com/devops
  2. https://appdevelopermagazine.com/devops-threats-report-released-from-gitprotect-io/
8/12/2024 7:40:50 AM
DevOps threats report released from GitProtect io
State of DevOps Threats Report,GitProtect.io,Security,GitHub,GitLab,Atlassian
https://news-cdn.moonbeam.co/DevOps-threats-report-released-from-GitProtect-io-App-Developer-Magazine_e6rsjove.jpg
App Developer Magazine
DevOps threats report released from GitProtect io

DevOps

DevOps threats report released from GitProtect io


Monday, August 12, 2024

Brittany Hainzinger Brittany Hainzinger

The State of DevOps Threats Report by GitProtect.io highlights the growing risks facing DevOps teams, with incidents like outages, cyberattacks, and data breaches occurring frequently. The report details significant vulnerabilities and attacks on platforms such as GitHub, GitLab, and Atlassian, providing crucial security practices for 2024.

Outages, human errors, cyberattacks, data breaches, ransomware, security vulnerabilities,
and, as a result, data loss are the reality that DevSecOps teams have to face...even every
few days.

The State of DevOps threats report - teams affected every few days

GitProtect.io recently presented its studies on the most severe incidents affecting tools like GitHub, GitLab, Bitbucket, or Jira. The State of DevOps Threats Report sheds light on the most critical cybersecurity incidents concerning DevOps organizations of all time, recalling the most controversial headlines. It is the research on the number and size of incidents that occurred in the past year in GitHub, GitLab, and Atlassian. However, in order not to leave readers with a sense of threat, the authors have prepared a list of the best security practices DevSecOps teams should not ignore in the coming months.

The number of incidents in GitHub grew over 20% YTY

The number of incidents affecting GitHub users in 2023 increased by over 21% compared to the previous year. The first quarter of the year was the most active in this regard.

For GitHub, it was a year of a methodology called “RepoJacking.” Researchers from AquaSec concluded that 9 million repos could be vulnerable to this attack, the Checkmarx team discovered that GitHub’s vuln could have exposed over 4K packages to RepoJacking, and finally, VulnCheck had been investigating this issue and found out that over 15K Go module repos were vulnerable to this kind of attack.

Hackers also used GitHub for hosting malware on a legitimate public service and used it as a dead-drop resolver to retrieve the real command-and-control (C2) address, giving a threat actor the green light to create an attack infrastructure that was reliable and inexpensive, and threatened other users and their data.

Atlassian suffers one third of the major impact incidents

Atlassian suffers one-third of the major impact incidents. Jira users were affected every 5 days.

About one-third of incidents Atlassian recognized as the major impact, which means that users experienced their occurrence in some ways. The number of incidents related to Bitbucket in 2023 decreased slightly compared to the previous year but we are talking about a difference of 2.04%. Unfortunately, Jira users could experience 50% more incidents than a year before - 75 events in total. It gives us worrying statistics of one incident every 5 days.

Last year Atlassian struggled mostly with high-severity flaws, with CVSS scores over 9 - template injection vulnerability or critical Remote Code Execution (RCE) bugs - just to name a few. Atlassian also fell victim to an attack on one of its employees, which resulted in the leak of the company's internal data.

32 percent of events in GitLab impacted service performance and customers

32% of events in GitLab impacted service performance and customers

About 32 percent of events in GitLab were recognized as having an impact on service performance, preventing customers from performing with full capabilities.

In August GitLab fell victim to a highly skilled assault that not only undermined the service provider’s security but also made an innovative Proxyjacking scheme possible. Initially, the attackers managed to gain access to the container using the CVE-2021-22205 vulnerability flaw (CVSS score of 10.0) which could ultimately open the door for ransomware, data theft, and other follow-on attacks. What was GitLab’s security advice? Of course, to follow the organization’s Security Incident and Disaster Recovery processes to revoke the compromised instance and restore the latest good working backup to a new GitLab instance.

Among other significant events, we can mention RCE flaws, a social engineering campaign that targeted the personal accounts of technology companies’ employees, critical account takeover flaws in GitLab, and more.

The report also analyzes the most serious incidents of all time, including the infamous Atlassian outage that lasted over 2 weeks, the GitLab database incident caused by human error that resulted in the loss of data from over 5,000 projects and 700 new users, and the ransomware attack and repository wipes of all three vendors. All of this is covered with a detailed explanation, a case study description, and recommendations for the future.

Addressing security risks - DevOps security best practices for 2024

Speaking of recommendations - the study describes in-depth security measures for protecting DevOps tool users' data, such as penetration testing and automated continuous security monitoring, least privilege principles, vulnerability management, and, above all, best practices for DevOps data backup and Disaster Recovery prepared by GitProtect.io cybersecurity experts and available for free in The State of DevOps Threat Report.


Subscribe to App Developer Magazine

Become a subscriber of App Developer Magazine for just $5.99 a month and take advantage of all these perks.

MEMBERS GET ACCESS TO

  • - Exclusive content from leaders in the industry
  • - Q&A articles from industry leaders
  • - Tips and tricks from the most successful developers weekly
  • - Monthly issues, including all 90+ back-issues since 2012
  • - Event discounts and early-bird signups
  • - Gain insight from top achievers in the app store
  • - Learn what tools to use, what SDK's to use, and more

    Subscribe here