FreshRSS

๐Ÿ”’
โŒ About FreshRSS
There are new available articles, click to refresh the page.
Before yesterdayYour RSS feeds

The time has come: GitHub expands 2FA requirement rollout March 13

A GitHub-made image accompanying all the company's communications about 2FA.

Enlarge / A GitHub-made image accompanying all the company's communications about 2FA. (credit: GitHub)

Software development tool GitHub will require more accounts to enable two-factor authentication (2FA) starting on March 13. That mandate will extend to all developers who contribute code on GitHub.com by the end of 2023.

GitHub announced its plan to roll out a 2FA requirement in a blog post last May. At that time, the company's chief security officer said that it was making the move because GitHub (which is used by millions of software developers around the world across myriad industries) is a vital part of the software supply chain. Said supply chain has been subject to several attacks in recent years and months, and 2FA is a strong defense against social engineering and other particularly common methods of attack.

When that blog post was written, GitHub revealed that only around 16.5 percent of active GitHub users used 2FAโ€”far lower than you'd expect from technologists who ought to know the value of it.

Read 6 remaining paragraphs | Comments

GoDaddy says a multi-year breach hijacked customer websites and accounts

A cartoon man runs across a white field of ones and zeroes.

Enlarge (credit: Getty Images)

GoDaddy said on Friday that its network suffered a multi-year security compromise that allowed unknown attackers to steal company source code, customer and employee login credentials, and install malware that redirected customer websites to malicious sites.

GoDaddy is one of the worldโ€™s largest domain registrars, with nearly 21 million customers and revenue in 2022 of almost $4 billion. In a filing Thursday with the Securities and Exchange Commission, the company said that three serious security events starting in 2020 and lasting through 2022 were carried out by the same intruder.

โ€œBased on our investigation, we believe these incidents are part of a multi-year campaign by a sophisticated threat actor group that, among other things, installed malware on our systems and obtained pieces of code related to some services within GoDaddy,โ€ the company stated. The filing said the companyโ€™s investigation is ongoing.

Read 6 remaining paragraphs | Comments

โŒ