news.mlab.sh
Back to the feed
threat-intel

Novo Nordisk Breach Exposes Software Development Pipeline Risk

High
Image: Dark Reading
Summary

A breach at Novo Nordisk, facilitated by a leaked GitHub token, exposed a significant amount of sensitive data, including patient clinical trial information, healthcare professional records, and proprietary drug development data. The attackers, identified as FulcrumSec and TheUSERS007, gained initial access through the token and subsequently exfiltrated over 1.3TB of data, highlighting vulnerabilities in software development pipelines and the importance of robust secrets management. This incident underscores the risk posed by developer environments and the potential for attackers to leverage access to code repositories for extensive data theft and disruption.

Read the full article at Dark Reading

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.