Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Red Hat Confirms Data Breach After Hackers Claim to Steal 570GB of Private GitHub Repositories

Red Hat Confirms Data Breach After Hackers Claim to Steal 570GB of Private GitHub Repositories

Posted on October 3, 2025October 3, 2025 By CWS

Purple Hat, the world’s main enterprise open-source software program supplier, has formally confirmed a big safety incident involving unauthorized entry to its inner GitLab occasion utilized by the Purple Hat Consulting group. 

This affirmation comes after the risk actor group often called Crimson Collective claimed to have exfiltrated roughly 570GB of compressed information from 28,000 personal repositories, marking probably the most substantial supply code breaches in latest cybersecurity historical past.

Non-public GitLab Repository Compromised

The breach particularly focused a GitLab surroundings utilized for Purple Hat Consulting collaboration throughout choose shopper engagements. 

In keeping with Purple Hat’s official assertion, the unauthorized third celebration efficiently accessed and copied delicate information from this occasion earlier than safety groups detected the intrusion. 

The corporate instantly launched a complete investigation, revoked the attacker’s entry, remoted the compromised occasion, and contacted acceptable regulation enforcement authorities.

The stolen information allegedly encompasses an unlimited array of delicate technical belongings, together with CI/CD secrets and techniques, pipeline configuration recordsdata, VPN connection profiles, infrastructure blueprints, Ansible playbooks, OpenShift deployment guides, container registry configurations, and Vault integration secrets and techniques. 

‼️🚨 Purple Hat breached: Crimson Collective stole 28k personal repositories, together with credentials, CI/CD secrets and techniques, pipeline configs, VPN profiles, and infrastructure blueprints.Our evaluation of obtained information: 👇 pic.twitter.com/ECMYLlHqyj— Worldwide Cyber Digest (@IntCyberDigest) October 1, 2025

Safety researchers analyzing the claimed breach information have recognized references to 1000’s of organizations throughout a number of crucial sectors, together with main monetary establishments like Citi, JPMC, and HSBC, telecommunications giants similar to Verizon and Telefonica, industrial firms together with Siemens and Bosch, and even authorities entities just like the U.S. Senate.

The breach represents a complicated provide chain assault vector that might probably affect Purple Hat’s intensive buyer ecosystem. 

The uncovered repositories reportedly include Infrastructure-as-Code (IaC) templates, DevOps automation scripts, and credential administration configurations that adversaries might leverage for secondary infiltration makes an attempt in opposition to Purple Hat’s consulting purchasers. 

The presence of SSH keys, API tokens, and database connection strings throughout the compromised information creates a number of assault vectors for risk actors looking for to determine persistent entry to downstream techniques.

Safety consultants warn that the leaked container registry configurations and Kubernetes deployment manifests might present attackers with detailed blueprints for concentrating on cloud-native infrastructures throughout Purple Hat’s shopper base. 

The publicity of GitLab CI/CD runner configurations and automatic deployment pipelines significantly issues cybersecurity professionals, as these parts usually include elevated privileges mandatory for enterprise software program deployment and administration.

Purple Hat has carried out extra hardening measures to stop additional unauthorized entry and said that preliminary evaluation signifies no affect on their main software program provide chain or official software program distribution channels. 

Nonetheless, the corporate continues conducting forensic evaluation to find out the total scope of buyer affect, with direct notifications deliberate for any affected Purple Hat Consulting purchasers. 

The incident stays unrelated to the just lately disclosed CVE-2025-10725 vulnerability affecting Purple Hat OpenShift AI providers.

Comply with us on Google Information, LinkedIn, and X for day by day cybersecurity updates. Contact us to function your tales.


Cyber Security News Tags:570GB, Breach, Claim, Confirms, Data, GitHub, Hackers, Hat, Private, Red, Repositories, Steal

Post navigation

Previous Post: Microsoft Defender for Endpoint Bug Triggers Numerous False BIOS Alerts
Next Post: Red Hat Confirms GitLab Instance Hack, Data Theft

Related Posts

Microsoft’s New Update Enhances Windows 11 Security Microsoft’s New Update Enhances Windows 11 Security Cyber Security News
Microsoft Desktop Windows Manager Out-Of-Bounds Vulnerability Let Attackers Escalate Privileges Microsoft Desktop Windows Manager Out-Of-Bounds Vulnerability Let Attackers Escalate Privileges Cyber Security News
BeaverTail Variant via Malicious Repositories Targeting Retail Sector Organizations BeaverTail Variant via Malicious Repositories Targeting Retail Sector Organizations Cyber Security News
Microsoft Teams Enhances Security by Removing EXIF Data Microsoft Teams Enhances Security by Removing EXIF Data Cyber Security News
Mozilla Warns of Phishing Attacks Targeting Add-on Developers Account Mozilla Warns of Phishing Attacks Targeting Add-on Developers Account Cyber Security News
Iranian Nation-State APT Targeting Networks and Critical Infrastructure Organizations Iranian Nation-State APT Targeting Networks and Critical Infrastructure Organizations Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Russian Intelligence Phishing Campaign Targets Messaging Apps
  • Chinese Framework Fuels Massive Scam Network
  • OpenAI Unveils GPT-5.6 Sol with Enhanced Security
  • Critical Cloud Bucket Hijacking Threat Exposed
  • Claude Mythos 5 Redeployed to Protect US Infrastructure

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark