logo

Cisco source code stolen in Trivy-linked dev environment breach

ID: 0d8b970e-9187-5283-a851-593798c3ba3f

STIX ID: report--0d8b970e-9187-5283-a851-593798c3ba3f

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-03-31

Date Updated: 2026-04-20

Author: Lawrence Abrams

...
...

Cisco was breached after attackers leveraged a malicious GitHub Action delivered through the Trivy supply-chain compromise to steal CI/CD credentials, clone over 300 repositories (including corporate and customer source code), and exfiltrate AWS keys; security teams contained the initial breach, are reimaging systems and rotating credentials, and investigators link the activity to the TeamPCP group and related supply-chain campaigns.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.