It has been reported today by several news outlets that there was a major security breach at Uber. The short story is, the intruders got access to an AWS account through an AWS Access Key and Secret Key stored in a Git repository, where they were stored in clear text. They were then able to get into instances that had access to databases storing sensitive data, and downloaded several million records worth of Personally Identifiable Information.
It´s scary to think about intruders accessing your data, but it´s totally preventable with some simple controls in place, so make sure you automate it away! Make checking for any potentials credentials in your repo part of your CI/CD Pipeline with a few tools that we recommend:
back to top