Cisco source code stolen in Trivy-linked dev environment breach
Cisco suffered a cyberattack where threat actors used stolen credentials from a recent Trivy supply chain attack to breach its internal development environment.
Key points
- Internal development environment breached.
- Stolen credentials from Trivy supply chain attack used.
- Multiple AWS keys stolen.
Connected intelligence
Signal brief
Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.
Organization
- Published
- Mar 31, 2026
- Updated
- Jun 25, 2026
- Confidence
- Medium
- Evidence
- 1 source
Structured assessment
Signal analysis
It helps compare this signal with other published signals without treating the labels as final determinations.
Threat source
Watch exposure paths that could affect data, operations or third-party trust.
Business impact
- Impact area
- Unknown
- Likely asset
- Server or cloud data store
Mentioned entities
Quick context
Questions about this signal
What happened in this signal?
Cisco suffered a cyberattack where threat actors used stolen credentials from a recent Trivy supply chain attack to breach its internal development environment. Attackers stole multiple AWS keys, cloned over 300 GitHub repositories, and accessed source code belonging to Cisco and its customers, including those related to AI Assistants, AI Defense, and unreleased products.
When was this signal reported?
Shadow Tier lists Mar 31, 2026 as the signal date.
Which organization is connected to this signal?
Cisco is the organization connected to this public signal.
Explore CiscoWhich impact area is relevant?
This signal is connected to data exposure and breach intelligence based on its reported consequences.
Explore data exposure and breach intelligence