Comment on Matrix.org Security IncidentparentComments−deepwell7yit was not, read again−PerceptesOP7yBut it does seem to be the case that the same SSH key pair that was used to access Jenkins also provided access to the production infrastructure. Unless I'm misunderstanding the nature of the attack.−zigara7yIt seems the issue was developers using SSH agent forwarding which was abused to access the production environment.
Comments
it was not, read again
But it does seem to be the case that the same SSH key pair that was used to access Jenkins also provided access to the production infrastructure. Unless I'm misunderstanding the nature of the attack.
It seems the issue was developers using SSH agent forwarding which was abused to access the production environment.