FBI: Hackers exploiting configuration vulnerabilities in SonarQube instances to gain access to source code repositories of U.S. government agencies and private businesses. The FBI alert was originally distributed to organizations as a private alert in October, but published publicly Tuesday to the bureau’s Internet Crime Complaint Center. The agency notes that the activity was similar to a previous data leak in July where unidentified hackers exfiltrated proprietary source code from enterprises and published the stolen source code on a self-hosted public repository.”]
Source: https://www.fraudtoday.io/federal-source-code-accessed-via-misconfigured-sonarqube-a-15303

