Skip to content
Better HN
Top
New
Best
Ask
Show
Jobs
Search
⌘K
0 points
Perceptes
6y ago
0 comments
Share
But it does seem to be the case that the same SSH key pair that was used to access Jenkins also provided access to the production infrastructure. Unless I'm misunderstanding the nature of the attack.
undefined | Better HN
0 comments
default
newest
oldest
zigara
6y ago
It seems the issue was developers using SSH agent forwarding which was abused to access the production environment.
j
/
k
navigate · click thread line to collapse