The hacker group Crimson Collective claimed to have gained access to one of Red Hat's internal GitLab servers and downloaded 570GB of compressed data containing information from 28,000 repositories. Among other things, the captured data included around 800 Customer Engagement Reports (CERs) containing confidential information about the platforms and network infrastructures of Red Hat clients who were provided with consulting services.
The screenshots and examples presented by the attackers mention accessing data related to about 800 Red Hat clients, including Vodafone, T-Mobile, Siemens, Boeing, Bosch, 3M, Cisco, DHL, Adobe, American Express, Verizon, JPMC, HSBC, Ericsson, Merrick Bank, Telefonica, Bank of America, Delta Air Lines, Walmart, Kaiser, IBM, SWIFT, IKEA, and AT&T, as well as the U.S. Navy's Surface Warfare Center, the Federal Aviation Administration, the Federal Emergency Management Agency, the U.S. Air Force, the National Security Agency, the U.S. Patent and Trademark Office, the U.S. Senate, and the House of Representatives.
It is claimed that the seized repositories contain information about client infrastructure, configuration, authentication tokens, profiles VPN, inventory data, Ansible playbooks, OpenShift platform settings, CI/CD runners, backups, and other data that could be used to organize an attack on the internal networks of clients. The attackers tried to contact Red Hat for extortion but received only a template response suggesting they submit a vulnerability report to the security service.
Red Hat confirmed the security incident but did not provide details or comment on the content of the leak. It is only mentioned that the hacked GitLab server was used in the consulting division, and the company has taken necessary steps for investigation and recovery. Red Hat representatives assert that they have no reason to believe that the breach affected other services and products of the company, apart from one сервера GitLab.
Shtesë: Kompania Red Hat publikoi një raport fillestar mbi incidentin. Në raport nuk jepen detaje, vetëm se kompania filloi një hetim, gjatë të cilit u zbulua se një person i panjohur kishte aksesuar serverin GitLab, i cili përdoret për menaxhimin e projekteve të ekipit të Konsulencës Red Hat, dhe shkarkoi disa të dhëna nga ai.
Sa i përket të dhënave të shkarkuara nga sulmuesi, thuhet se ato përfshinin specifikime projektesh, shembuj kodi dhe materiale informuese të brendshme mbi shërbimet e konsulencës. Në këtë fazë të analizës së incidentit, deritani nuk është identifikuar ndonjë rrjedhje e të dhënave personale të rëndësishme.
Nuk saktësohet se si sulmuesi arriti të aksesojë serverin GitLab, por thuhet se në sulm nuk u përdor vulnerabiliteti i zbuluar dje (CVE-2025-10725) në OpenShift AI Service, i cili i lejon një përdoruesi të autentifikuar, p.sh., një kërkues që përdor Jupyter notebook, të marrë të drejtat e administratorit të klasterit, i cili ka akses të plotë në të gjitha shërbimet, të dhënat dhe aplikacionet e nisura në klaster, si dhe akses root në nyjat e klasterit.
Burimi: opennet.ru
