Skip to content

Security builletin: ASEC-24-002 #464

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
Dec 12, 2024
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
---
title: "ASEC-24-002 - Security incident on Arduino infrastructure"
---

Bulletin ID: ASEC-24-002
Date: Dec 12, 2024
Product / Component: Arduino web infrastructure

## Summary

We have recently been made aware that a hacker published a set of information related to our infrastructure on a dark web forum. Our Security Team has investigated the claim and our incident response process has been immediately implemented.

To our knowledge, a leaked API access key has briefly been used to download PDF files representing certificates of completion of Arduino courses, which is not harmful information to our users. The leak was immediately remediated.

This exposure is related to a security incident that happened some months ago, to which we promptly reacted by taking adequate countermeasures. At the moment we have no evidence that the incident can result in harm to the security of our Arduino Web and Cloud services.
We remain committed to provide the highest security standards and thank you, our community, for your trust and support.

## Contact

If you encounter any issues or have questions regarding this security update, please contact our security team at [email protected].
Loading