[TheRecord] Azure, GitHub, GitLab, BitBucket mass-revoke SSH keys following bug report

Microsoft, GitHub, GitLab, and BitBucket —four of today’s largest code hosting portals— have initiated mass revocations of SSH keys on Monday after the discovery of a vulnerability in a popular Git software client named GitKraken.

The mass revocations come at the request of Arizona-based software company Axosoft, which developed GitKraken and is the one who found the security flaw in its own software.

In a blog post on Monday, Axosoft explained that versions 7.6.x, 7.7.x, and 8.0.0 of its GitKraken app used a library named “keypair” to generated SSH keys to allow developers to connect their GitKraken app to accounts on Azure DevOps, GitHub, GitLab, BitBucket, or other remote Git source code hosting servers.

But Axosoft said that older versions of this library generated RSA keys with low entropy, meaning that attackers could use the library, under certain conditions, to generate duplicate SSH keys.

The attacker could then use these keys to access a user’s account and steal proprietary source code.

Axosoft said that as soon as it learned of the issue, it replaced the keypair library inside the GitKraken app, released version 8.0.1, and notified the four platforms.

Shortly after Axosoft’s blog post, the security teams of Azure DevOpsGitHubGitLab, and Atlassian’s BitBucket have started revoking all SSH keys connected to accounts where the GitKraken app was used to synchronize source code.

The four platforms are now asking users to generate new SSH keys using a different Git client or using an updated GitKraken app.

Both Axosoft and the four platforms said they haven’t found evidence that attackers used this bug to compromise accounts — so far.

In addition, GitHub also asked the developers of other software applications —not only Git clients— to check and see if they are using the vulnerable keypair library in their apps, and update their code accordingly. The keypair library also received a security update on Monday.

The post Azure, GitHub, GitLab, BitBucket mass-revoke SSH keys following bug report appeared first on The Record by Recorded Future.

Source: Read More (The Record by Recorded Future)

You might be interested in …

[ZDNet] One third of cybersecurity workers have faced harassment at work or online – this initiative aims to stamp it out

All posts, ZDNet

Respect In Security is encouraging organisations to create a workplace free from abuse. Source: Read More (Latest topics for ZDNet in Security)

Read More

[ZDNet] Arrests were made, but the Mekotio Trojan lives on

All posts, ZDNet

Law enforcement cut off tails, but not the head of the cybercriminal operation. Source: Read More (Latest topics for ZDNet in Security)

Read More

[SecurityWeek] Zyxel Warns Customers of Attacks on Security Appliances

All posts, Security Week

Networking device manufacturer Zyxel has issued an alert to warn customers of attacks targeting a subset of security appliances that have remote management or SSL VPN enabled. read more Source: Read More (SecurityWeek RSS Feed)

Read More