Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Security notice: Beware of spear phishing

Дата публикации: 06-10-2026 00:36:29


Canny, the third-party tool behind our feedback and roadmap board, recently experienced a security incident. This was a breach at Canny, not of CircleCI’s own systems. We’re sharing what we know and what we recommend.
What happened
On August 29th, 2026 Canny reported to CircleCI that an unauthorized party accessed one of its internal systems and retrieved API keys and integration credentials. Canny terminated the access on August 28, rotated its keys, and engaged an outside forensics firm. Canny states that passwords are stored hashed and salted, and that 2FA secrets are encrypted. The hashed passwords were within the scope of what was exfiltrated from Canny. In response, Canny reset all Canny passwords.
What we’ve done
CircleCI’s security team opened an incident on August 31 and has:
Rotated our Canny API and SSO keys and enforced Okta SSO for all Canny access
Disconnected Canny’s integrations with our other tools while each is verified
Reviewed audit logs and swept our telemetry for indicators of compromise
What you should do
Reset your password if you use ideas.circleci.com or circleci.canny.io
Never reuse that password elsewhere. If you did, change it everywhere.
Expect phishing. Names and emails from vendor breaches are commonly used for targeted messages.
Protecting yourself from spear phishing
Verify unexpected requests through a second channel, not by replying.
Be wary of urgency, especially around credentials, payments, or “security fixes.”
Check sender domains and link destinations for look-alikes.
Use phishing-resistant MFA (passkeys or hardware keys), and never approve a prompt you didn’t initiate.
Reach CircleCI only through bookmarks or the app, never email links.
Rotate API tokens if you suspect exposure.
Report suspicious messages to security@circleci.com. CircleCI will never ask for your password, tokens, or MFA codes.
1 post - 1 participant
Read full topic


Основное содержимое страницы с новостью.

<------>

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Security advisory: Secrets in builds from forked pull requests05.602-05-2026
2GitHub Webhook Secret Exposure — Action Required for GitHub OAuth Projects011.6514-04-2026
3Reminder: Rotate credentials if you use Trivy in your CI/CD pipelines011.0420-03-2026
4OAuth 2.0 API Access with Dynamic Client Registration09.6812-08-2026
5The New Slack Integration is now in Beta06.0213-05-2026
6Changes to Unregistered User Billing on Committed Plans07.6409-03-2026
7Reminder: Rotate credentials if you use LiteLLM in your CI/CD pipelines010.3824-03-2026
8How to get email PDF invoices back?010.6125-09-2026
9CircleCI response to CVE-2026-31431 ("Copy Fail" Linux kernel vulnerability)06.7902-05-2026
10PocketCI - CircleCI in your pocket08.7929-09-2026

Классификация: Пресс-релизы. Схожих патентов: 0. Схожих новостей: 10. Тональность: 0. Информативность: 7.88. Источник: discuss.circleci.com.