{"id":83724,"date":"2024-03-18T22:15:28","date_gmt":"2024-03-18T22:15:28","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2024\/03\/18\/mintlify-says-customer-github-tokens-exposed-in-data-breach-techcrunch\/"},"modified":"2024-03-18T22:15:28","modified_gmt":"2024-03-18T22:15:28","slug":"mintlify-says-customer-github-tokens-exposed-in-data-breach-techcrunch","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2024\/03\/18\/mintlify-says-customer-github-tokens-exposed-in-data-breach-techcrunch\/","title":{"rendered":"Mintlify says customer GitHub tokens exposed in data breach | TechCrunch"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\">Documentation startup Mintlify says dozens of customers had GitHub tokens exposed in a data breach at the start of the month and publicly disclosed last week.<\/p>\n<p>Mintlify helps <a href=\"https:\/\/techcrunch.com\/2022\/05\/30\/mintlify-taps-ai-to-automatically-generate-documentation-from-code\/\" target=\"_blank\" rel=\"noopener\">developers create documentation<\/a> for their software and source code by requesting access and tapping directly into the customer\u2019s GitHub source code repositories. Mintlify counts fintech, database and AI startups as customers.<\/p>\n<p>In a blog post Monday, Mintlify blamed its March 1 incident on a vulnerability in its own systems, but said 91 of its customers had their GitHub tokens compromised as a result.<\/p>\n<p>These private tokens allow GitHub users to share their account access with third parties apps, including companies like Mintlify. If these tokens are stolen, an attacker could obtain the same level of access to a person\u2019s source code as the token permits.<\/p>\n<p>\u201cThe users have been notified, and we\u2019re working with GitHub to identify whether the tokens were used to access private repositories,\u201d Mintlify co-founder Han Wang wrote <a href=\"https:\/\/mintlify.com\/blog\/incident-march-13\" target=\"_blank\" rel=\"noopener\">in a blog post<\/a>.<\/p>\n<p>News of the incident became public last week when some users on Reddit and Hacker News commented after getting an email from Mintlify on Friday about the incident, days after the company\u2019s blog post initially told customers that \u201cno further action is required on your part.\u201d<\/p>\n<p>In a post discussing the breach <a href=\"https:\/\/news.ycombinator.com\/item?id=39736704\" target=\"_blank\" rel=\"noopener\">on Hacker News<\/a>, Wang said a vulnerability in its systems was leaking the company\u2019s internal admin credentials to customers. Those credentials could then be used to access the company\u2019s internal endpoints to access other unspecified sensitive user information, Wang said.<\/p>\n<p>Wang said that the company was in the process of deprecating the use of private tokens \u201cto prevent an incident like this from ever happening again.\u201d<\/p>\n<p>While the blog post describes the person who discovered the vulnerability as a bug bounty reporter, the company\u2019s co-founder Wang described the events as malicious.<\/p>\n<p>\u201cThe targets of this attack were GitHub tokens of our users,\u201d Wang told TechCrunch by email.<\/p>\n<p>\u201cInvestigations with one impacted customer revealed that the leaked token was likely not used by the attacker. We are currently working with GitHub and our customers to uncover if any of the other tokens were used by the attacker,\u201d Wang said.<\/p>\n<\/p><\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2024\/03\/18\/mintlify-customer-github-tokens-data-breach\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Documentation startup Mintlify says dozens of customers had GitHub tokens exposed in a data breach at the start of the month and publicly disclosed last week. Mintlify helps developers create documentation for their software and source code by requesting access and tapping directly into the customer\u2019s GitHub source code repositories. Mintlify counts fintech, database and [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":83725,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-83724","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/83724","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=83724"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/83724\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/83725"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=83724"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=83724"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=83724"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}