Security News

Cybersecurity news aggregator

📦
HIGH Attacks SecurityWeek

Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack

Grafana's GitHub repositories were compromised due to a supply chain attack against TanStack, where a stolen and unrotated GitHub workflow token provided unauthorized access. The attackers exfiltrated the company's codebase and internal operational data, including business contact information, but did not affect production systems or modify the stolen code. While no specific vulnerability details, CVSS scores, or affected software versions are provided in the article, the incident underscores the critical need to promptly rotate all credentials and access tokens following any related supply chain compromise.
Read Full Article →

Data Breaches Grafana Says Codebase and Other Data Stolen via TanStack Supply Chain Attack Hackers accessed Grafana’s GitHub repositories after a token compromised in the TanStack attack was not rotated. By Ionut Arghire | May 22, 2026 (3:49 AM ET) Flipboard Reddit Whatsapp Whatsapp Email Grafana this week revealed that the unauthorized access to the Grafana Labs GitHub repositories disclosed earlier this month was the result of the TanStack supply chain attack. On May 11, TanStack and other high-profile NPM and PyPI projects were hit by a Mini Shai-Hulud supply chain attack that resulted in self-propagating information-stealing malware being deployed on victims’ computers. Grafana says it detected malicious activity associated with the attack on May 11 and immediately rotated GitHub workflow tokens. Because one token was not revoked, however, the threat actor behind the TanStack attack accessed Grafana’s GitHub repositories. “A subsequent review confirmed that a specific GitHub workflow we originally deemed not impacted had, in fact, been compromised,” Grafana says. On May 16, Grafana received a ransom demand from the attackers, but refused to pay. Simultaneously, it launched additional mitigation efforts, hardened its GitHub posture, and notified law enforcement. Advertisement. Scroll to continue reading. “Current findings indicate the scope of this incident is limited to the Grafana Labs GitHub repositories, which include public and private source code along with internal GitHub repos,” Grafana says. While no customer production systems or operations were affected, the hackers did steal Grafana’s codebase, as well as repositories storing internal operational information and other business details. “This includes business contact names and email addresses that would be exchanged in a professional relationship context, not information pulled from or processed through the use of production systems or the Grafana Cloud platform,” Grafana says. The incident, it explains, did not affect its production systems, nor the Grafana Cloud platform. Furthermore, Grafana says, while its codebase was downloaded, it was not modified, and no action is needed from customers or open source users. Related: Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility Related: AI-Powered App Attacks Are Faster, More Frequent and Harder to Stop Related: Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack Related: OpenAI Hit by TanStack Supply Chain Attack Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Microsoft Rolls Out Mitigations for ‘YellowKey’ BitLocker Bypass Over 320 NPM Packages Hit by Fresh Mini Shai-Hulud Supply Chain Attack GitHub Confirms Hack Impacting 3,800 Internal Repositories Verizon DBIR 2026: Vulnerability Exploitation Overtakes Credential Theft as Top Breach Vector Unpatched ChromaDB Vulnerability Can Lead to Server Takeover B1ack’s Stash Marketplace Gives Away 4.6 Million Stolen Credit Cards 201 Arrested in Crackdown on Cybercrime in Middle East, North Africa PoC Released for DirtyDecrypt Linux Kernel Vulnerability Latest News Cisco Patches Critical Vulnerability in Secure Workload Ocean Emerges From Stealth With $28M for Agentic Email Security Platform Apple Rejected 2 Million App Store Submissions in 2025 for Security and Fraud Prevention Drupal Patches Highly Critical Vulnerability Exposing Websites to Hacking Socket Raises $60 Million at $1 Billion Valuation Microsoft Patches Exploited UnDefend and RedSun Defender Zero-Days Google’s Surge in Chrome Vulnerability Discoveries Likely Driven by AI Supply Chain Security Crisis: Too Many Vulnerabilities, Too Little Visibility Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Virtual Event: Threat Detection and Incident Response Summit May 20, 2026 Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization. Register Webinar: Third-Party Risk in Practice June 4, 2026 Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice. Register People on the Move Joe Chen has become Chief Technology Officer at Trellix. Usercentrics has named Pawan Hegde as COO and Elena Ignatova as CPTO. SecureAuth has named Mark van Oppen as Chief Revenue Officer. More People On The Move Expert Insights Caught Off Guard: Securing AI After It Hits Production As enterprises rush AI projects into production, security teams are increasingly being forced into reactive mode. (Joshua Goldfarb) Cyber Resilience is the New Business Continuity Plan The organizations best prepared to face disruption are those that align security, continuity and risk management around what the business cannot afford to lose. (Steve Durbin) Enhancing Data Center Security Without Sacrificing Performance For AI data centers, where the stakes are the highest and performance constraints are the tightest, security and performance are no longer a zero-sum game. (Nadir Izrael) Is the SOC Obsolete, and We Just Haven’t Admitted It Yet? Many AI-first enterprises have already embraced sovereign architectures for general AI initiatives; cybersecurity—and the SOC—should be next. (Danelle Au) The Mythos Moment: Enterprises Must Fight Agents with Agents Only with the right platform and an agentic, AI-driven defense, will enterprises be able to protect themselves in the agentic era. (Etay Maor) Flipboard Reddit Whatsapp Whatsapp Email

Share this article