·CRITICAL8.6·confirmed
CircleCI Session Token Breach (2023)
Malware on a CircleCI engineer's laptop stole a 2FA-backed session token, giving the attacker production access to customer environment variables and any secrets stored in CircleCI.
벡터 / CI/CD compromise플랫폼 / CircleCI, GitHub, AWS분량 / 3분