Hacker News new | past | comments | ask | show | jobs | submit login

FYI looks like the stolen Heroku OAuth tokens are already being used:

https://github.blog/2022-04-15-security-alert-stolen-oauth-u...




Both heroku and travisci were affected? I wonder if and what the common vector would be for two major providers to lose their OAuth tokens.


- Heroku might be using Travis? - They were compromise independently but the hackers decided to start leveraging them at the same time to get the most out of them? - The obvious common denominator: Github? It doesn't make a lot of sense though.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: