Skip to main content
Back to overview
Medium

Cisco source code stolen in Trivy-linked dev environment breach

Cisco suffered a cyberattack where threat actors used stolen credentials from a recent Trivy supply chain attack to breach its internal development environment.

Key points

  • Internal development environment breached.
  • Stolen credentials from Trivy supply chain attack used.
  • Multiple AWS keys stolen.

Connected intelligence

Signal brief

Follow the organization, likely method and potential impact to explore connected Shadow Tier intelligence.

02

Likely method

Explore attack patterns

Threat source not confirmed

03

Potential impact

Data Exposure

Impact remains under assessment

Published
Mar 31, 2026
Updated
Jun 25, 2026
Confidence
Medium
Evidence
1 source

Structured assessment

Signal analysis

It helps compare this signal with other published signals without treating the labels as final determinations.

Threat source

Threat source not confirmed

Watch exposure paths that could affect data, operations or third-party trust.

Business impact

Potential business exposure
Impact area
Unknown
Likely asset
Server or cloud data store

Mentioned entities

CiscoCiscoTrivy-linkedTrivyAttackersAWSGitHubCisco andAI AssistantsAI Defense

Quick context

Questions about this signal

What happened in this signal?

Cisco suffered a cyberattack where threat actors used stolen credentials from a recent Trivy supply chain attack to breach its internal development environment. Attackers stole multiple AWS keys, cloned over 300 GitHub repositories, and accessed source code belonging to Cisco and its customers, including those related to AI Assistants, AI Defense, and unreleased products.

When was this signal reported?

Shadow Tier lists Mar 31, 2026 as the signal date.

Which organization is connected to this signal?

Cisco is the organization connected to this public signal.

Explore Cisco
Which impact area is relevant?

This signal is connected to data exposure and breach intelligence based on its reported consequences.

Explore data exposure and breach intelligence