Thursday, May 5, 2022

Heroku admits to customer database hack after OAuth token theft

Heroku has now revealed that the stolen GitHub integration OAuth tokens from last month further led to the compromise of an internal customer database. The Salesforce-owned cloud platform acknowledged the same compromised token was used by attackers to exfiltrate customers' hashed and salted passwords from "a database." [...] Posted at https://sl.advdat.com/384mWv7