SAML Single Sign-On (SSO) Integration
Unmasking password attacks at GitLab

Unmasking password attacks at GitLab

9/28/2023 · GitLab Security Team

What this post added

This post details the identification and mitigation of increased password attacks against the OAuth API endpoint on GitLab.com, highlighting the use of automated attacks targeting simple usernames. GitLab is increasing security measures, monitoring activities, and recommending user-level precautions such as enabling two-factor authentication, enforcing it at the group level, using IP address restrictions for group access, and implementing Git Abuse Rate Limiting. The post also advises on general security hygiene like using strong, unique passwords and being vigilant against phishing.

Read the original post ↗