DevOps threats report released from GitProtect io

Posted on Monday, August 12, 2024 by BRITTANY HAINZINGER, Social Editor

Outages, human errors, cyberattacks, data breaches, ransomware, security vulnerabilities,
and, as a result, data loss are the reality that DevSecOps teams have to face...even every
few days.

The State of DevOps threats report - teams affected every few days

GitProtect.io recently presented its studies on the most severe incidents affecting tools like GitHub, GitLab, Bitbucket, or Jira. The State of DevOps Threats Report sheds light on the most critical cybersecurity incidents concerning DevOps organizations of all time, recalling the most controversial headlines. It is the research on the number and size of incidents that occurred in the past year in GitHub, GitLab, and Atlassian. However, in order not to leave readers with a sense of threat, the authors have prepared a list of the best security practices DevSecOps teams should not ignore in the coming months.

The number of incidents in GitHub grew over 20% YTY

The number of incidents affecting GitHub users in 2023 increased by over 21% compared to the previous year. The first quarter of the year was the most active in this regard.

For GitHub, it was a year of a methodology called “RepoJacking.” Researchers from AquaSec concluded that 9 million repos could be vulnerable to this attack, the Checkmarx team discovered that GitHub’s vuln could have exposed over 4K packages to RepoJacking, and finally, VulnCheck had been investigating this issue and found out that over 15K Go module repos were vulnerable to this kind of attack.

Hackers also used GitHub for hosting malware on a legitimate public service and used it as a dead-drop resolver to retrieve the real command-and-control (C2) address, giving a threat actor the green light to create an attack infrastructure that was reliable and inexpensive, and threatened other users and their data.


Atlassian suffers one-third of the major impact incidents. Jira users were affected every 5 days.

About one-third of incidents Atlassian recognized as the major impact, which means that users experienced their occurrence in some ways. The number of incidents related to Bitbucket in 2023 decreased slightly compared to the previous year but we are talking about a difference of 2.04%. Unfortunately, Jira users could experience 50% more incidents than a year before - 75 events in total. It gives us worrying statistics of one incident every 5 days.

Last year Atlassian struggled mostly with high-severity flaws, with CVSS scores over 9 - template injection vulnerability or critical Remote Code Execution (RCE) bugs - just to name a few. Atlassian also fell victim to an attack on one of its employees, which resulted in the leak of the company's internal data.


32% of events in GitLab impacted service performance and customers

About 32 percent of events in GitLab were recognized as having an impact on service performance, preventing customers from performing with full capabilities.

In August GitLab fell victim to a highly skilled assault that not only undermined the service provider’s security but also made an innovative Proxyjacking scheme possible. Initially, the attackers managed to gain access to the container using the CVE-2021-22205 vulnerability flaw (CVSS score of 10.0) which could ultimately open the door for ransomware, data theft, and other follow-on attacks. What was GitLab’s security advice? Of course, to follow the organization’s Security Incident and Disaster Recovery processes to revoke the compromised instance and restore the latest good working backup to a new GitLab instance.

Among other significant events, we can mention RCE flaws, a social engineering campaign that targeted the personal accounts of technology companies’ employees, critical account takeover flaws in GitLab, and more.

The report also analyzes the most serious incidents of all time, including the infamous Atlassian outage that lasted over 2 weeks, the GitLab database incident caused by human error that resulted in the loss of data from over 5,000 projects and 700 new users, and the ransomware attack and repository wipes of all three vendors. All of this is covered with a detailed explanation, a case study description, and recommendations for the future.

Addressing security risks - DevOps security best practices for 2024

Speaking of recommendations - the study describes in-depth security measures for protecting DevOps tool users' data, such as penetration testing and automated continuous security monitoring, least privilege principles, vulnerability management, and, above all, best practices for DevOps data backup and Disaster Recovery prepared by GitProtect.io cybersecurity experts and available for free in The State of DevOps Threat Report.

More App Developer News

How AI is causing app litter everywhere



The App Economy Is Thriving



NIKKE 3.5 anniversary update livestream coming soon



New AI tool targets early dementia detection



Jentic launch gives AI agents api access



Experts warn ai-generated health content risks misinterpretation without human oversight



Ludo.ai Unveils API and MCP Beta to Power AI Game Asset Pipelines



AccuWeather Launches ChatGPT Integration for Live Weather Updates



Stop Using Business Jargon: 5 Ways Buzzwords Damage Job Performance



IT spending rises as banks balance legacy and innovation



Tech hiring slumps as Software Developer job postings fall



AI is becoming more widespread in collaboration tools



FCC prohibits new foreign router models citing critical infrastructure risks



ChatGPT Carbon Footprint Matches 1.3 Million Cars Report Finds



Lens Launches MCP Server to Connect AI Coding Assistants with Kubernetes



Accelerating corporate ai investment returns



Enviromates tech startup launches global participation platform



Private Repository Secures the AI-driven Development Boom



UK Fintech Platform Enviromates Connects Projects Brands and Consumers



Env Zero and CloudQuery Announce Merger



How Industrial AI Is Transforming Operations in 2026



AI generated work from managers is damaging trust among employees



Foresight Secures $25M to Bridge Infrastructure Execution Gap



UNESCO AI initiatives driving sustainable development in Africa



What can you build with ChatGPT in 48 hours



Copyright © 2026 by Moonbeam

Address:
1855 S Ingram Mill Rd
STE# 201
Springfield, Mo 65804

Phone: 1-844-277-3386

Fax:417-429-2935

E-Mail: contact@appdevelopermagazine.com