Canny, the third-party tool behind our feedback and roadmap board, recently experienced a security incident. This was a breach at Canny, not of CircleCI’s own systems. We’re sharing what we know and what we recommend.
What happened
On August 29th, 2026 Canny reported to CircleCI that an unauthorized party accessed one of its internal systems and retrieved API keys and integration credentials. Canny terminated the access on August 28, rotated its keys, and engaged an outside forensics firm. Canny states that passwords are stored hashed and salted, and that 2FA secrets are encrypted. The hashed passwords were within the scope of what was exfiltrated from Canny. In response, Canny reset all Canny passwords.
What we’ve done
CircleCI’s security team opened an incident on August 31 and has:
Rotated our Canny API and SSO keys and enforced Okta SSO for all Canny access
Disconnected Canny’s integrations with our other tools while each is verified
Reviewed audit logs and swept our telemetry for indicators of compromise
What you should do
Reset your password if you use ideas.circleci.com or circleci.canny.io
Never reuse that password elsewhere. If you did, change it everywhere.
Expect phishing. Names and emails from vendor breaches are commonly used for targeted messages.
Protecting yourself from spear phishing
Verify unexpected requests through a second channel, not by replying.
Be wary of urgency, especially around credentials, payments, or “security fixes.”
Check sender domains and link destinations for look-alikes.
Use phishing-resistant MFA (passkeys or hardware keys), and never approve a prompt you didn’t initiate.
Reach CircleCI only through bookmarks or the app, never email links.
Rotate API tokens if you suspect exposure.
Report suspicious messages to security@circleci.com. CircleCI will never ask for your password, tokens, or MFA codes.
1 post - 1 participant
Read full topic
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Security advisory: Secrets in builds from forked pull requests | 0 | 5.6 | 02-05-2026 |
| 2 | GitHub Webhook Secret Exposure — Action Required for GitHub OAuth Projects | 0 | 11.65 | 14-04-2026 |
| 3 | Reminder: Rotate credentials if you use Trivy in your CI/CD pipelines | 0 | 11.04 | 20-03-2026 |
| 4 | OAuth 2.0 API Access with Dynamic Client Registration | 0 | 9.68 | 12-08-2026 |
| 5 | The New Slack Integration is now in Beta | 0 | 6.02 | 13-05-2026 |
| 6 | Changes to Unregistered User Billing on Committed Plans | 0 | 7.64 | 09-03-2026 |
| 7 | Reminder: Rotate credentials if you use LiteLLM in your CI/CD pipelines | 0 | 10.38 | 24-03-2026 |
| 8 | How to get email PDF invoices back? | 0 | 10.61 | 25-09-2026 |
| 9 | CircleCI response to CVE-2026-31431 ("Copy Fail" Linux kernel vulnerability) | 0 | 6.79 | 02-05-2026 |
| 10 | PocketCI - CircleCI in your pocket | 0 | 8.79 | 29-09-2026 |