The world has learned of serious breaches affecting chat service Slack and software testing and delivery company CircleCI, though given the companies’ cryptic language—”security issue” and “security incident,” respectively—you’d be forgiven for thinking these were minor occurrences.
The compromises—in Slack’s case, the theft of employee token credentials; in CircleCI’s case, the possible exposure of all customer secrets stored—come just two weeks after password manager LastPass revealed its own security failure: the theft of customers’ password vaults containing sensitive data in both encrypted and clear text form. It’s unclear whether all three breaches are connected, but it’s certainly a possibility.