Cisco says some files recently stolen from a public-facing DevHub portal do not contain information that could be used for future breaches of the company's systems .

The company reviewed the exposed documents and found that their content includes data the company publishes for customers and other users of DevHub. There were, of course, some files that should not have been made public , and some of them belonged to CX Professional Services customers. Cisco said it will personally notify all customers affected by the breach.
See also: Cisco patches vulnerability that allows Brute-Force
The company said its teams are continuing to assess the content of the exposed files, but so far no information has been identified that could be used by the attacker to gain access to any business or production environment.
Cisco has fixed the configuration and restored public access to the compromised DevHub site. Last month, the company was forced to take its DevHub site (a customer resource center where software code, templates, and scripts are published) offline after data was leaked by an attacker.
See also: Vulnerabilities in Cisco Small Business Routers Allow Remote Exploitation
The company added that it found no evidence that any financial data or personal information.
IntelBroker , who is behind this breach, reportedly told BeelpingComputer that it also gained access to a Cisco JFrog developer environment , via an exposed API token.
According to the files shared by IntelBroker with BeelpingComputer, there was access to source code, configuration files with database credentials, technical documentation, and SQL files.
While Cisco says its systems have not been compromised, the information shared indicates a third-party development environment.
See also: Cisco patches serious vulnerabilities in IOS software

To avoid such breaches, companies like Cisco must take some preventive protection measures:
Regular assessments for potential vulnerabilities: Thorough assessments should be conducted regularly to identify potential weaknesses in systems. This allows them to address problems immediately, before they are exploited by hackers.
Multi-factor authentication (MFA): In addition to traditional password protection, MFA is required for all employees who have access to sensitive systems. This adds an extra layer of security to prevent unauthorized access.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Employee Training: Regular training and education programs should be provided for employeesto raise awareness about cybersecurity best practices. This not only helps prevent internal breaches, but also strengthens the company’s overall security posture.
Strong Incident Response Plan: In the event of a breach, companies should have a well-defined incident response plan in place. This ensures a rapid and coordinated response to potential threats, minimizing their impact on company operations.
Source: www.bleepingcomputer.com
