Skip to content

Commit 31b1c90

Browse files
authored
Security builletin: ASEC-24-002 (#464)
Create ASEC-24-002-Security-incident-on-Arduino-infrastructure.md
1 parent 5e67efb commit 31b1c90

File tree

1 file changed

+20
-0
lines changed

1 file changed

+20
-0
lines changed
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,20 @@
1+
---
2+
title: "ASEC-24-002 - Security incident on Arduino infrastructure"
3+
---
4+
5+
Bulletin ID: ASEC-24-002
6+
Date: Dec 12, 2024
7+
Product / Component: Arduino web infrastructure
8+
9+
## Summary
10+
11+
We have recently been made aware that a hacker published a set of information related to our infrastructure on a dark web forum. Our Security Team has investigated the claim and our incident response process has been immediately implemented.
12+
13+
To our knowledge, a leaked API access key has briefly been used to download PDF files representing certificates of completion of Arduino courses, which is not harmful information to our users. The leak was immediately remediated.
14+
15+
This exposure is related to a security incident that happened some months ago, to which we promptly reacted by taking adequate countermeasures. At the moment we have no evidence that the incident can result in harm to the security of our Arduino Web and Cloud services.
16+
We remain committed to provide the highest security standards and thank you, our community, for your trust and support.
17+
18+
## Contact
19+
20+
If you encounter any issues or have questions regarding this security update, please contact our security team at [email protected].

0 commit comments

Comments
 (0)