← BrowserStack

2014 BrowserStack — Shellshock (CVE-2014-6271); EC2 compromise; customer email outreach

2014 Unknown records affected Share on X

Data compromised

User account–oriented contact and credential-hash descriptions in 2014 press; exact categories per BrowserStack’s incident communications

Technical writeup

In November 2014, cross-browser testing vendor BrowserStack attributed a production intrusion to exploitation of the Shellshock bash flaw on an inadequately patched machine, with contemporaneous reporting describing access to infrastructure including AWS-oriented material and follow-on abuse that included emailing portions of its user base. Public statements and security press framed exposure around account-related metadata (e.g., email and password-hash narratives in news coverage) rather than a single regulator-normalized victim tally.

Root cause

Unpatched bash / Shellshock-exploitable service exposed to network attack path

References