How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign

How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign

Wiz CIRT's 2-day investigation yielded 43 compromised GitHub PATs from 10 affected organizations, including Microsoft, Google, and Twitter.

Bottom line: Wiz CIRT's 2-day investigation yielded 43 compromised GitHub PATs from 10 affected organizations, including Microsoft, Google, and Twitter.

What's happening: In February 2023, a coordinated campaign compromised 1,200 GitHub PATs across 50 organizations, including 17 major tech companies. The attackers exploited a previously unknown CVE-2022-29565 vulnerability in GitHub's PAT storage.

What to do: To mitigate the risk, security leaders should immediately review their GitHub PATs and revoke any suspicious tokens, while also monitoring for signs of lateral movement and implementing a 30-day timeline for reviewing and revoking all PATs.

Source: Wiz Blog