
9/28/2023 · GitLab Security Team
What this post added
This post details the identification and mitigation of increased password attacks against the OAuth API endpoint on GitLab.com, highlighting the use of automated attacks targeting simple usernames. GitLab is increasing security measures, monitoring activities, and recommending user-level precautions such as enabling two-factor authentication, enforcing it at the group level, using IP address restrictions for group access, and implementing Git Abuse Rate Limiting. The post also advises on general security hygiene like using strong, unique passwords and being vigilant against phishing.