Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 18, 2026 (about 4 months ago).

market · May 18, 2026

Grafana Labs Discloses GitHub Token Breach Allowing Codebase Download

Share the canonical public link.

Share as image

Grafana Labs disclosed on May 16, 2026 that an unauthorized party obtained a privileged token granting access to its GitHub environment and downloaded the company's private codebase. The company identified the intrusion after a canary token triggered an alert and determined the root cause was a misconfigured GitHub Action workflow vulnerable to pull_request_target events. Grafana Labs invalidated the compromised credentials, removed the vulnerable workflow, disabled workflows across public repositories, and refused a ransom demand citing FBI guidance that payments incentivize further attacks. Grafana Labs investigation found no customer data or personal information was accessed and no evidence of impact to customer systems or operations. Grafana Labs will share additional findings from its post-incident review once investigations complete.

Spend governor blocked model creation: provider_circuit_open (lane=dev, provider=together)

Supporting evidence