HomeSecurityDatadog: RPM signing key changes after CircleCi attack

Datadog: RPM signing key changes after CircleCi attack

According to Datadog , a cloud security company, one of the RPM ( aka Red-hat Package Manager ) GPG signing keys and its “password” was exposed during a recent info-stealing hack targeting CircleCi . – An RPM signature, like the digital signature used in many other software signing systems, is an encryption of a checksum with a private key. RPM uses the GPG libraries for signing. – The company has not found any evidence that the key was actually leaked or used in any malicious way, however, the company is taking precautionary measures. See also: Malicious PyPi ‘Lolip0p’ packages install info-stealing malware





Datadog: RPM signing key changes after CircleCi attack

Following the CircleCi attack , Datadog released an updated version of the Agent 5 RPM for CentOS/RHEL (a Linux distribution) that is signed with a new key. They also created a Linux installation script that removes the compromised key from Datadog’s repository repository has not been compromised. file and RPM database. Datadog’s Even if an attacker were able to obtain the signing key and create a malicious RPM package, they would not be able to target Datadog customers. They would need access to the official repositories , which the company said has not happened, and that the signing key – if indeed leaked – could only be used to create a package that would only appear to come from Datadog itself. Datadog advises customers to ensure that their systems stop trusting the affected signing key, delete it , and verify that all installed packages are built by the company itself using the instructions provided . See also:








Datadog: RPM signing key changes after CircleCi attack

Datadog posted this information on its “documentation” page as a “FAQ,” which is not prominently displayed on the company’s website, next to the other FAQ sections, for example. BleepingComputer was unable to locate the page in a search, as Datadog has set “values” for the “ noindex ” and “ nofollow ” metadata tags. When contacted for more information, Datadog was unable to comment, as no representative was available at the time . A domino effect has begun, with info-stealing malware stealing a session cookie from the laptop of one of CircleCi’s engineers. We’ll see what happens next. Source: bleepingcomputer.com






📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS