惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Stack Overflow Blog
Stack Overflow Blog
T
Tailwind CSS Blog
Recent Announcements
Recent Announcements
宝玉的分享
宝玉的分享
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
P
Proofpoint News Feed
D
Docker
Google DeepMind News
Google DeepMind News
aimingoo的专栏
aimingoo的专栏
B
Blog RSS Feed
Microsoft Security Blog
Microsoft Security Blog
博客园 - 【当耐特】
M
MIT News - Artificial intelligence
云风的 BLOG
云风的 BLOG
小众软件
小众软件
Hugging Face - Blog
Hugging Face - Blog
WordPress大学
WordPress大学
IT之家
IT之家
H
Help Net Security
Apple Machine Learning Research
Apple Machine Learning Research
Martin Fowler
Martin Fowler
S
SegmentFault 最新的问题
B
Blog
D
DataBreaches.Net

Enterprise – Silicon Republic

FT: Hackers demand $3m ransom from Revolut after data breach Recovery readiness a missing link in cyber resilience, finds report EU finally gets its hands on Anthropic’s Mythos New Irish dispute body to tackle illegal online content launched Rhysida leaks 5.7TB of sensitive Berlin state data in major hack ‘Keeping OT security up to date is more than patching systems’ HSE fined €645,000 for storing records in decrepit conditions Boston Scientific cyberattack: Cork staff asked to work remotely Report: Only sectors aiding AI adoption sure to grow from it Why connectivity and cybersecurity can't be treated separately French authorities investigating hack of national tax authority Why employee retention is at the heart of the cyber skills gap Levi Strauss corporate data stolen in cyberattack Levi Strauss corporate data stolen in cyberattack How might a system ‘leak secrets’ without being hacked? What is a side-channel attack in cybersecurity? OpenAI agents breach Modal client system after Hugging Face hack OpenAI agents breach Modal client system after Hugging Face hack Report: EMEA businesses not reaping benefits from their AI spend Report: EMEA businesses not reaping benefits from their AI spend Transport for London hackers jailed for five and a half years Transport for London hackers jailed for five and a half years Commission refers Ireland to CJEU for failing to enact cyber rules Commission refers Ireland to CJEU for failing to enact cyber rules Cloudflare to block AI crawlers from ad-supported webpages by default Cloudflare to block AI crawlers from ad-supported webpages by default Google ordered to pay Klarna nearly $2bn in abuse-of-power row Google ordered to pay Klarna nearly $2bn in abuse-of-power row Upcoming iPhone 18 model leaked in Tata Electronics hack New iPhone 18 models reportedly leaked in Tata Electronics hack
Hackers access GitHub, download codebase in Grafana Labs ...
Laura Varley · 2026-05-18 · via Enterprise – Silicon Republic

The hackers have since demanded a ransom payment from Grafana Labs to prevent the release of its codebase.

US software company Grafana Labs has confirmed a breach in which hackers gained access to the organisation’s GitHub system after stealing a private token and downloaded the company’s codebase.  

A provider of an open-source and visualisation web app with 25m users and more than 7,000 customers, including Anthropic, Bloomberg, Nvidia, Microsoft and Salesforce, Grafana Labs has a presence in more than 40 countries. 

In a statement posted on LinkedIn, Grafana Labs said, “Our investigation has determined that no customer data or personal information was accessed during this incident, and we have found no evidence of impact to customer systems or operations.

“We immediately initiated forensic analysis and we believe we’ve identified the source of the credential leak. We have since invalidated the compromised credentials and implemented additional security measures to further secure our environment against unauthorised access.”

The intruder or group – whose identity has yet to be confirmed – sent Grafana Labs a payment demand, threatening to release the stolen code. However, the organisation has refused to comply with the request.

Grafana Labs said, “Based on our operational experience and the published stance of the Federal Bureau of Investigation, which notes that ‘paying a ransom doesn’t guarantee you or your organisation will get any data back’ and only ‘offers an incentive for others to get involved in this type of illegal activity’, we have determined the appropriate path forward is to not pay the ransom.”

The company also stated that as part of its standard security practices, it will share information as part of a post-incident review once the investigation is complete.

Earlier this month, Taiwanese electronics manufacturer Foxconn confirmed a cyberattack affecting its North American operations, after a hacking group claimed to have stolen 8TB of data from it. Nitrogen claimed that the extracted files included confidential instructions, internal project documentation and technical drawings related to projects involving Intel, Apple, Google, Dell, Nvidia and other companies.

And prior to that, Instructure, the parent company behind Canvas, the education management platform reportedly hacked by ShinyHunters, reached an agreement with the cyber gang in which the group has returned stolen data, deleted copies and agreed not to extort client institutions affected in the hack – for unknown compensation.   

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.