惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

L
LangChain Blog
C
Check Point Blog
月光博客
月光博客
Y
Y Combinator Blog
I
InfoQ
B
Blog RSS Feed
P
Proofpoint News Feed
腾讯CDC
博客园 - Franky
MyScale Blog
MyScale Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
V
V2EX
Hugging Face - Blog
Hugging Face - Blog
V
Visual Studio Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
云风的 BLOG
云风的 BLOG
罗磊的独立博客
B
Blog
人人都是产品经理
人人都是产品经理
Engineering at Meta
Engineering at Meta
MongoDB | Blog
MongoDB | Blog
Recent Announcements
Recent Announcements
美团技术团队
大猫的无限游戏
大猫的无限游戏

Enterprise – Silicon Republic

FT: Hackers demand $3m ransom from Revolut after data breach Recovery readiness a missing link in cyber resilience, finds report EU finally gets its hands on Anthropic’s Mythos New Irish dispute body to tackle illegal online content launched Rhysida leaks 5.7TB of sensitive Berlin state data in major hack ‘Keeping OT security up to date is more than patching systems’ HSE fined €645,000 for storing records in decrepit conditions Boston Scientific cyberattack: Cork staff asked to work remotely Report: Only sectors aiding AI adoption sure to grow from it Why connectivity and cybersecurity can't be treated separately French authorities investigating hack of national tax authority Why employee retention is at the heart of the cyber skills gap Levi Strauss corporate data stolen in cyberattack Levi Strauss corporate data stolen in cyberattack How might a system ‘leak secrets’ without being hacked? What is a side-channel attack in cybersecurity? OpenAI agents breach Modal client system after Hugging Face hack OpenAI agents breach Modal client system after Hugging Face hack Report: EMEA businesses not reaping benefits from their AI spend Report: EMEA businesses not reaping benefits from their AI spend Transport for London hackers jailed for five and a half years Transport for London hackers jailed for five and a half years Commission refers Ireland to CJEU for failing to enact cyber rules Commission refers Ireland to CJEU for failing to enact cyber rules Cloudflare to block AI crawlers from ad-supported webpages by default Cloudflare to block AI crawlers from ad-supported webpages by default Google ordered to pay Klarna nearly $2bn in abuse-of-power row Google ordered to pay Klarna nearly $2bn in abuse-of-power row Upcoming iPhone 18 model leaked in Tata Electronics hack New iPhone 18 models reportedly leaked in Tata Electronics hack
Hackers access GitHub, download codebase in Grafana Labs ...
Laura Varley · 2026-05-18 · via Enterprise – Silicon Republic

The hackers have since demanded a ransom payment from Grafana Labs to prevent the release of its codebase.

US software company Grafana Labs has confirmed a breach in which hackers gained access to the organisation’s GitHub system after stealing a private token and downloaded the company’s codebase.  

A provider of an open-source and visualisation web app with 25m users and more than 7,000 customers, including Anthropic, Bloomberg, Nvidia, Microsoft and Salesforce, Grafana Labs has a presence in more than 40 countries. 

In a statement posted on LinkedIn, Grafana Labs said, “Our investigation has determined that no customer data or personal information was accessed during this incident, and we have found no evidence of impact to customer systems or operations.

“We immediately initiated forensic analysis and we believe we’ve identified the source of the credential leak. We have since invalidated the compromised credentials and implemented additional security measures to further secure our environment against unauthorised access.”

The intruder or group – whose identity has yet to be confirmed – sent Grafana Labs a payment demand, threatening to release the stolen code. However, the organisation has refused to comply with the request.

Grafana Labs said, “Based on our operational experience and the published stance of the Federal Bureau of Investigation, which notes that ‘paying a ransom doesn’t guarantee you or your organisation will get any data back’ and only ‘offers an incentive for others to get involved in this type of illegal activity’, we have determined the appropriate path forward is to not pay the ransom.”

The company also stated that as part of its standard security practices, it will share information as part of a post-incident review once the investigation is complete.

Earlier this month, Taiwanese electronics manufacturer Foxconn confirmed a cyberattack affecting its North American operations, after a hacking group claimed to have stolen 8TB of data from it. Nitrogen claimed that the extracted files included confidential instructions, internal project documentation and technical drawings related to projects involving Intel, Apple, Google, Dell, Nvidia and other companies.

And prior to that, Instructure, the parent company behind Canvas, the education management platform reportedly hacked by ShinyHunters, reached an agreement with the cyber gang in which the group has returned stolen data, deleted copies and agreed not to extort client institutions affected in the hack – for unknown compensation.   

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.