Hasty Briefsbeta

Bilingual

CrowdSec Source Code Leak

4 hours ago
  • CrowdSec was notified on September 16 about a source code leak from its GitHub repository that occurred in May 2026.
  • The leak involves private repositories containing SaaS console, AWS routines, connectors, and automations, but public FOSS code is unaffected.
  • No client data, PII, or credentials were leaked; only an API token for CI/CD was exposed.
  • The leaked code has limited harm potential as CrowdSec's value relies on network effect and size, not just code.
  • The leak vector is suspected to be a backdoored Tanstack component used in May 2026, similar to the Mistral AI case.
  • All necessary tokens and credentials were rotated immediately to prevent further incidents.