close
close
Your Network of Tomorrow
Your Network of Tomorrow
Plan your path toward a faster, more secure, and more resilient network designed for the applications and users that you support.
            Experience Netskope
            Get Hands-on With the Netskope Platform
            Here's your chance to experience the Netskope One single-cloud platform first-hand. Sign up for self-paced, hands-on labs, join us for monthly live product demos, take a free test drive of Netskope Private Access, or join us for a live, instructor-led workshops.
              A Leader in SSE. Now a Leader in Single-Vendor SASE.
              Netskope is recognized as a Leader Furthest in Vision for both SSE and SASE Platforms
              2X a Leader in the Gartner® Magic Quadrant for SASE Platforms
              One unified platform built for your journey
                ""
                Netskope One AI Security
                Organizations need secure AI to move their business forward, but controls and guardrails must not require sacrifices in speed or user experience. Netskope can help you say yes to the AI advantage.
                  ""
                  Netskope One AI Security
                  Organizations need secure AI to move their business forward, but controls and guardrails must not require sacrifices in speed or user experience. Netskope can help you say yes to the AI advantage.
                    Modern data loss prevention (DLP) for Dummies eBook
                    Modern Data Loss Prevention (DLP) for Dummies
                    Get tips and tricks for transitioning to a cloud-delivered DLP.
                      Modern SD-WAN for SASE Dummies Book
                      Modern SD-WAN for SASE Dummies
                      Stop playing catch up with your networking architecture
                        Understanding where the risk lies
                        Advanced Analytics transforms the way security operations teams apply data-driven insights to implement better policies. With Advanced Analytics, you can identify trends, zero in on areas of concern and use the data to take action.
                            Netskope Technical Support
                            Netskope Technical Support
                            Our qualified support engineers are located worldwide and have diverse backgrounds in cloud security, networking, virtualization, content delivery, and software development, ensuring timely and quality technical assistance
                              Netskope video
                              Netskope Training
                              Netskope training will help you become a cloud security expert. We are here to help you secure your digital transformation journey and make the most of your cloud, web, and private applications.

                                Cloud Threats Memo: Tightening Up Leaky GitHub Repositories

                                Mar 08 2022

                                Another day, another cloud service leaking personal data because of a misconfiguration. And before you jump to any conclusions, no, it’s not a leaky bucket on AWS S3 or a public blob on Microsoft Azure…

                                The culprit is, once again, GitHub, where an open-source hardware manufacturer has inadvertently left exposed a private-to-public repository that “could have enabled unauthorized access to information about certain user accounts on or before 2019.”

                                The exposed information involved an auditing data set used for employee training stored on a GitHub repository associated with an inactive former employee’s account. The data set contained some names, email addresses, shipping/billing addresses, and/or whether orders were placed successfully via credit card processor and/or PayPal, as well as details for some orders.

                                Luckily there were no user passwords or financial information such as credit cards in the data analysis set, however, this aspect does not make it any less relevant that multiple errors were involved in this incident: GitHub is not supposed to store personal information; even worse production data should never be used for tests or training; and, last but not least, specific procedures should be in place to secure former employees’ accounts.

                                Even if the leaked records do not contain credit card information, they are still interesting for threat actors, for example, to launch targeted phishing campaigns.

                                This is another example that shows how difficult it is for many organizations to shift their procedures and mindsets to a cloud-native environment.

                                How Netskope mitigates the risk of leaky cloud applications

                                The Netskope Next Gen SWG, part of the Netskope Intelligent SSE platform, provides granular in-line controls for GitHub (and thousands of additional SaaS and IaaS applications) including adaptive access control, DLP, and threat protection. Netskope can recognize and govern dozens of activities for GitHub (such as upload, download, create and share), and in this specific case can prevent the upload of PII to a public repository (or coach the user when such activity is detected).

                                Additional out-of-band controls are possible via the CASB API module (for example, an organization can be alerted if a repository is made public) and via the SaaS Security Posture Management (SSPM) module where specific checks in the app can be performed to ensure it is compliant with best practices, standards, and regulations (for example a specific control for GitHub can ensure that there are no inactive users or repositories).

                                Similar out-of-band controls are available for AWS, Microsoft Azure, and Google Cloud Platform via the Public Cloud Security module.

                                In all cases, Netskope Advanced Analytics provides specific dashboards to identify data movements across corporate and personal instances.

                                Stay safe!

                                author image
                                Paolo Passeri
                                Paolo supports Netskope’s customers in protecting their journey to the cloud and is a security professional, with 20+ years experience in the infosec industry.
                                Paolo supports Netskope’s customers in protecting their journey to the cloud and is a security professional, with 20+ years experience in the infosec industry.
                                Connect with Netskope

                                Subscribe to the Netskope Blog

                                Sign up to receive a roundup of the latest Netskope content delivered directly in your inbox every month.