2024 DevOps Threats Unwrapped

The most severe flaws, prolonged outages, devastating human errors, data breaches, and other incidents that shaped the DevSecOps cybersecurity landscape last year.

26

major impact issues

134hrs

of disruption

github GitHub 2024 report
github
4

major impact issues

4hrs

of disruption

bitbucket Bitbucket 2024 report
bitbucket
10

major impact issues

17hrs

of disruption

jira Jira 2024 report
jira
7

major impact issues

798hrs

of disruption

gitlab GitLab 2024 report
gitlab
1

major impact issues

~2hrs

of disruption

azure Azure DevOps 2024 report
azure

955 hrs in total, which is enough to cross the Atlantic by small yacht, with a short break in the Caribbean, reach the East Coast and then go back to Europe.

Month with the largest number of incident

July

64 incidents in total,
52% above the median

Month with the longest time of disruptions

June

Service Disruption started
on 06.06 and lasted ~779 hrs

Issues
heatmap

GitHub GitHub
Bitbucket Bitbucket
Jira Jira
GitLab GitLab
Azure DevOps Azure DevOps
arrow-dropdown
January
9
2
7
4
no data
February
9
10
15
6
12
March
8
2
7
6
7
April
18
2
5
10
12
May
11
2
10
3
10
June
8
6
6
5
15
July
20
5
5
12
22
August
11
2
15
7
5
September
11
4
18
17
6
October
4
0
19
9
7
November
7
2
14
8
12
December
8
1
11
10
3

Top 3 targeted
industries

  1. Technology and Software

    Targeted companies
    • Wordpress
    • Ultralytics
    • Acuity
  2. Fintech and Banking

    Targeted companies
    • Ginco
    • ByteFederal
    • Iress
  3. Media and Entertainment

    Targeted companies
    • New York Times
    • Disney

Reported
incidents

github

GitHub recorded 124 incidents in 2024, the lowest in three years, following 136 incidents in 2022 and 165 in 2023. The most turbulent period was Q3, with 42 incidents, while Q1 saw the highest number of major-impact cases - 8 in total. In Q2, seven incidents lasted a combined over 80 hours, adding to the overall disruption.

Security threats also persisted, with GitHub patching 18 vulnerabilities in the first half of the year. In October, GitHub addressed a critical flaw with a CVSS score of 9.5, which could have allowed attackers to bypass SAML SSO authentication and gain unauthorized access. At the same time, during the year threat actors intensified their efforts, with thousands of "ghost accounts" spreading malware. Hackers also expanded their tactics by embedding malicious payloads not only in repositories but also in comment sections, making detection even more challenging.

Read more
bitbucket

Bitbucket experienced a decline in incidents in 2024, with 38 recorded cases compared to 48 in 2023, seeing a 21% decrease. However, the total downtime still amounted to over 207 hours with about half of the incidents classified by Atlassian as of major and critical impacts. The first quarter was the most disruptive, with 14 incidents lasting a total of 132 hours, and February stood out as the most active month with 10 incidents in total.

Last year, security remained a significant concern, with 20 high-severity vulnerabilities patched, all carrying a CVSS score above 7.4. Threat actors leveraged different schemes using ransomware and malware strains like BeaverTail and OtterCookie to steal data. Also, hackers exploited plaintext AWS authentication secrets exposed in Atlassian Bitbucket artifact objects in their attempts to breach accounts.

Read more
jira

With a nearly 30% increase in the total number of incidents in Jira Software, Jira Work Management, and Jira Service Management, Atlassian experienced in 2024 - there were 132 issues recorded compared to 91 incidents in 2023. The most disruptive period was the fourth quarter with 44 incidents, while Q3 saw the highest number of critical issues, leading to Jira services being hard down for some time.

Security threats remained a major concern, with 45 vulnerabilities patched throughout the year - 77% of them in the second half alone. Among the most severe vulnerabilities was a critical SQL injection flaw with a CVSS score of 9.8, posing a significant risk of allowing an attacker to inject SQL under specific conditions. Hackers also targeted Jira users in persistent attempts to steal corporate data.

Read more
gitlab

In 2024 GitLab saw an almost 21% increase in recorded incidents, 96 issues, in 2023 there were only 76 incidents. Critical issues made up about 7% of the total, 7 incidents, with a combined lasting time of over 798 hours… almost 100 working days! September was the most turbulent month, with 17 incidents recorded and impacting Git operations, API, CI/CD, etc. in different measures from service disruption to degraded performance.

Security was a key focus, with 153 vulnerabilities discovered and patched throughout the year. More than half - 83 flaws - were addressed in the first half of 2024 alone. One of the most severe threats was an authentication bypass vulnerability with a CVSS score of 10, which could have allowed attackers to log in as arbitrary users.

Read more
azure

The number of incidents affecting Azure DevOps in 2024 reached over 110 recorded cases with the total performance degradation time exceeding 826 hours… It equals over 103 working days! The second quarter of the year was the most active in regard to incidents while Q3 saw the longest period of degraded performance, lasting over 555 hours. In August, a misconfiguration in an internal service using Azure Front Door led to a major outage impacting users across Latin and North America.

Security concerns also took center stage with a critical vulnerability that allowed attackers to manipulate server-side requests, impersonate trusted Azure services, and bypass network controls based on Service Tags. This flaw created a serious risk, potentially exposing internal assets, sensitive data, and services to unauthorized access.

Read more

Get the latest DevSecOps insights

Learn DevOps backup best practices

github-big

GitHub Backup Best Practices

Read more
github-1

Infamous GitHub-related Incidents And Threats: 2023 in Review

January 5, 2024 Read more
github-2

GitHub Security Best Practices – 15 Tips To Keep In Mind

February 28, 2023 Read more
github-3

Implementing A Repository And Metadata Backup Software For The Enterprise – A Case Study

October 27, 2023 Read more
bitbucket-big

Bitbucket Backup Best Practices

Read more
bitbucket-1

Atlassian security incidents: 2023 in Review

January 8, 2024 Read more
bitbucket-2

Atlassian Security Best Practices

February 16, 2023 Read more
bitbucket-3

Disaster Recovery: Bitbucket Ecosystem – What Are The Best Scenarios & Use Cases

August 2, 2023 Read more
gitlab-big

GitLab Backup And Restore Best Practices [Step-by-step tutorial]

Read more
gitlab-1

GitLab Vulnerabilities And Security Incidents: 2023 In Review

January 10, 2024 Read more
gitlab-2

GitLab Restore And Disaster Recovery – How To Eliminate Data Loss

April 5, 2023 Read more
gitlab-3

GitLab Backup to S3

September 12, 2022 Read more