2 min read

How We Took Over a Flagship App Using Stolen GitHub Credentials

Our Security Assessment team is constantly looking for creative ways to identify vulnerabilities. Geoff Robinson, Principal Consultant at ivision, shares how he gained unauthorized access by stealing a developer’s GitHub credentials.

Using those credentials, Geoff was able to inject a malicious action in to a GitHub runner host, which had access to the internal network. This granted him access to view all of the organization’s microservices. From there, Geoff exploited an authorization flaw in the Management API, and he was able to take control of the flagship application.

This goes to show that organizations must be sealed tight at every entry point. Reach out to ivision’s Security Assessment team today to gain full visibility of your environment and receive personalized recommendations to improve your security posture.