GitHub warns Desktop, Atom users after code-signing certificates pinched | Computer Weekly
Summary
GitHub has issued an urgent warning to users of its Desktop for Mac and Atom text editor applications after an unauthorised actor broke into its systems and stole two encrypted DigiCert code-signing certificates used for Windows and one Apple Developer ID certificate, which could potentially have given them access to some of its development and release planning repositories. “Once detected on 7 December 2022, our team immediately revoked the compromised credentials and began investigating potential impact to customers and internal systems. We have no evidence that the threat actor was able to decrypt or use these certificates.” As a preventative measure, it will be revoking the exposed certificates used, which will invalidate various versions of GitHub Desktop and Atom. “To protect against events such as these, which are becoming increasingly common, security engineering teams must deploy a control plane for automating machine identity management. When certificates are managed and configured manually, they can slip through the cracks, leaving enterprises vulnerable to outages or cyber attacks.