Sunday, Oct 11, 2026
English News
  • Hyderabad
  • Telangana
  • AP News
  • India
  • World
  • Entertainment
  • Sport
  • Science and Tech
  • Business
  • Rewind
  • ...
    • NRI
    • View Point
    • cartoon
    • My Space
    • Education Today
    • Reviews
    • Property
    • Lifestyle
E-Paper
  • NRI
  • View Point
  • cartoon
  • My Space
  • Reviews
  • Education Today
  • Property
  • Lifestyle
Home | Science & Tech | Hackers Stole Source Code From Govt Agencies Private Firms Fbi

Hackers stole source code from govt agencies, private firms: FBI

The FBI alert warned the owners of SonarQube, a web-based application that companies integrate into their software build chains to test source code and discover security flaws before rolling out code and applications into production environments.

By IANS
Updated On - 8 November 2020, 05:16 PM
Hackers stole source code from govt agencies, private firms: FBI
whatsapp facebook twitter telegram

San Francisco, Nov 8 (IANS) The US Federal Bureau of Investigation (FBI) has issued a security alert saying threat actors have stolen source code from government agencies and private firms and are abusing it to gain access to critical information.

The FBI alert warned the owners of SonarQube, a web-based application that companies integrate into their software build chains to test source code and discover security flaws before rolling out code and applications into production environments.


The actors exploit known configuration vulnerabilities, allowing them to gain access to proprietary code, exfiltrate it and post the data publicly.

The FBI has identified multiple potential computer intrusions that correlate to leaks associated with SonarQube configuration vulnerabilities.

“SonarQube apps are installed on web servers and connected to source code hosting systems like BitBucket, GitHub, or GitLab accounts, or Azure DevOps systems,” reports ZDNet.

According to the FBI, some companies have left these systems unprotected, running on their default configuration with default admin credentials.

“In August 2020, unknown threat actors leaked internal data from two organizations through a public lifecycle repository tool. The stolen data was sourced from SonarQube instances that used default port settings and admin credentials running on the affected organizations’ networks,” the FBI said in the alert.

This activity is similar toa previous data leak in July 2020, in which an identified cyber actor exfiltrated proprietary source code from enterprises through poorly secured SonarQube instances and published the exfiltrated source code on a self-hosted public repository.

The FBI suggested the firms change the SonarQube default settings, including changing default administrator username, password and port (9000).

“Place SonarQube instances behind a login screen, and check if unauthorized users have accessed the instance and revoke access to any application programming interface keys or other credentials that were exposed in a SonarQube instance, if feasible,” the agency suggested.

Join Our Whatsapp Channel
  • Follow Us :
As preferred source
  • Tags
  • Corona Virus Deaths
  • Coronavirus
  • Coronavirus in India
  • Coronavirus Latest Updates

Related News

  • Telangana Today-Namasthe Telangana Dasara Bonanza draws huge response in Hyderabad

    Telangana Today-Namasthe Telangana Dasara Bonanza draws huge response in Hyderabad

  • Hyderabad BTech student drowns in quarry while shooting Instagram reels

    Hyderabad BTech student drowns in quarry while shooting Instagram reels

  • KTR demands action against Gajwel MRO over alleged remarks to farmer

    KTR demands action against Gajwel MRO over alleged remarks to farmer

  • Apollo Medical College holds graduation ceremony for UG, PG batches

    Apollo Medical College holds graduation ceremony for UG, PG batches

Latest News

  • Archery Premier League: Chero Archers make it three wins in four matches

    8 seconds ago
  • PJTAU to hold third phase of counselling for Agriculture, Food Technology courses on Oct 14-15

    3 minutes ago
  • K. Laxman wins men’s Indian Round title at State archery meet

    18 minutes ago
  • Over 35,000 participate in Quambiant Global Grace Cancer Run in Hyderabad

    33 minutes ago
  • BITS Hyderabad edge Rahimpura 41-40 in basketball league thriller

    46 minutes ago
  • CV Anand hits unbeaten 107 as Secunderabad Club beat Tarakarama

    44 minutes ago
  • 31 UoH researchers feature in Stanford-Elsevier world’s top 2 pc scientists list

    37 minutes ago
  • Ramayana Part 1 release date confirmed for November 5, 2026

    1 hour ago

company

  • Home
  • About Us
  • Contact Us
  • Privacy Policy

business

  • Subscribe

telangana today

  • Telangana
  • Hyderabad
  • Latest News
  • Entertainment
  • World
  • Andhra Pradesh
  • Science & Tech
  • Sport

follow us

  • Telangana Today Telangana Today
Telangana Today Telangana Today

© Copyrights 2024 TELANGANA PUBLICATIONS PVT. LTD. All rights reserved. Powered by Veegam

Telangana Today App