惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

J
Java Code Geeks
GbyAI
GbyAI
Google DeepMind News
Google DeepMind News
Jina AI
Jina AI
B
Blog
aimingoo的专栏
aimingoo的专栏
酷 壳 – CoolShell
酷 壳 – CoolShell
T
The Blog of Author Tim Ferriss
Last Week in AI
Last Week in AI
月光博客
月光博客
H
Help Net Security
V
Visual Studio Blog
量子位
A
About on SuperTechFans
博客园 - Franky
人人都是产品经理
人人都是产品经理
N
Netflix TechBlog - Medium
云风的 BLOG
云风的 BLOG
雷峰网
雷峰网
Martin Fowler
Martin Fowler
Microsoft Security Blog
Microsoft Security Blog
博客园 - 叶小钗
P
Proofpoint News Feed
MongoDB | Blog
MongoDB | Blog

Mintlify Blog

22 UX improvements to the web editor Introducing the Mintlify Help Center Starter Kit Introducing the collaborative editor built for teams and agents Workflows, rebuilt Is your documentation agent-ready? Mintlify raises $45M Series B led by Andreessen Horowitz and Salesforce Ventures 5 things you didn't know you could do in the Mintlify web editor The improved Mintlify CLI Docs on autopilot: From zero to self-maintaining with Mintlify The state of agent traffic in documentation (March 2026) How we built a virtual filesystem for our Assistant We Replaced Our Internal Wiki With a Slack Bot. You Should Too. 8 ways teams use Mintlify to keep docs updated automatically Documentation is your AI interface What three years of watching AI in production taught us Bridging two JSX runtimes: How we solved Astro's React children problem AI agents are shipping faster than anyone can document Knowledge management systems for technical teams Workflows: Automate documentation maintenance Mintlify acquires Helicone to redefine AI knowledge infrastructure Why more product managers are switching to Mintlify Auto-generating documentation sites from GitHub repos Your docs, your frontend, our content engine Take control of your documentation system Almost half your docs traffic is AI, time to understand the agent experience @mintlify for better docs, faster Mintlify for Enterprise Real llms.txt examples from leading tech companies (and what they got right) Mintlify + Claude Opus 4.6: Powering AI-native knowledge management Declaring Clankruptcy: An experiment in agent orchestration
Incident report on March 13, 2024
Han Wang · 2024-03-13 · via Mintlify Blog

Edit March 18, 2024 10:20 AM

We've detected from our logs that 91 GitHub tokens were compromised. The users have been notified, and we're working with GitHub to identify whether the tokens were used to access private repositories.

On March 1st, we received an email raising concerns about the security of our endpoints. This in turn prompted us to rake through our logs and we discovered unusual requests to our servers originating from an unrecognized device.

Alarmingly, we noticed that some of these requests targeted sensitive API endpoints and were successful in their attempts. This unusual activity indicated that the actor behind these requests had possession of our private admin access tokens, granting them unauthorized access to our endpoints.

We received confirmation that GitHub tokens stored within our databases were used to access a customer's repository. While we do not have evidence of any other such instances, we cannot confirm that no other such instances occurred.

We took immediate action by revoking all GitHub token access, rotating our admin access tokens, and implementing stringent security measures to all of our APIs to mitigate any further unauthorized access. Additionally, we have patched the vulnerability that led to the exposure of our admin access tokens.

We have also since partnered with third-party cybersecurity vendors to conduct an extensive investigation, and have implemented other security measures to ensure that this type of unauthorized access cannot occur again. For the security of our users, we decided to implement those security measures before making this public announcement.

All timestamps referenced are in Pacific Daylight Time (PDT).

  • Friday, March 1 4:55PM - Received an email raising concerns about the security of our endpoints/potential leaking of our token.

  • Friday, March 1 6:41PM - Discovered logs of an unrecognized device accessing API endpoints.

  • Friday, March 1 6:51PM - Revoked all existing GitHub user access tokens.

  • Friday, March 1 6:51PM-11PM

    • Rotated our internal access tokens.
    • Enhanced security protocols around endpoint authorization to prevent unauthorized access.
    • Got in contact with a couple bug bounties.
  • Saturday, March 2nd and 3rd - Continued to stay in close contact with a bug bounty reporter, patched the vulnerability that resulted in the leak of our access token and revoked and rotated all tokens again.

No further action is required on your part to continue using our product safely.

Our team has addressed the vulnerability and taken steps to secure our systems against similar incidents in the future.

In our response to protect our users and our systems, these are the measure that we have already taken:

  • Revoked all existing GitHub user access tokens.
  • Rotated of our internal access tokens.
  • Patched the vulnerability that resulted in the leak of our access token.
  • Enhanced security protocols around endpoint authorization to prevent unauthorized access.
  • Received a penetration test.

These are ongoing preventing measures that we are currently taking:

  • Collaborating with leading cybersecurity firms, including Oneleet, and our other partners, to conduct a thorough investigation and fortify our defenses against potential future attacks.
  • Enhancing the monitoring and alerting systems for our API endpoints to detect and respond to unusual activities swiftly.
  • Developing a comprehensive security policy and establishing a public page dedicated to outlining our security measures and protocols.
  • Launching a bounty program to facilitate the reporting of security vulnerabilities from ethical hackers.
  • Re-auditing our SOC 2 certification for 2024.

We deeply regret the inconvenience and concern this incident may have caused. Our dedication to transparency, security, and the trust you place in us remains unwavering.

Your security and trust are the foundations upon which Mintlify is built. We are dedicated to ensuring the continued safety and security of your content and information.

Should you have any concerns or questions, please do not hesitate to contact us at [email protected].

Sincerely,

The Mintlify Team