Description

Cisco is currently managing a major cybersecurity incident involving unauthorized access to its internal development networks. Threat actors reportedly breached the environment and gained access to sensitive systems and data. The hacking group ShinyHunters has claimed responsibility, alleging the theft of critical information, including source code and data linked to Cisco, Salesforce, Aura, and several AWS storage resources. The breach is believed to have originated from a supply chain compromise involving Trivy, a widely used vulnerability scanning tool. Attackers exploited a malicious GitHub Action associated with the compromised tool to steal credentials, enabling them to bypass security controls and infiltrate Cisco’s internal build environments. Once inside, the attackers expanded their access by compromising multiple systems, including developer workstations and lab devices. This allowed them to access sensitive repositories and extract valuable data. Notably, several AWS access keys were reportedly stolen and misused to perform unauthorized actions within Cisco’s cloud infrastructure. Additionally, the attackers cloned over 300 private GitHub repositories containing proprietary source code, including unreleased tools and advanced technologies such as AI Assistants and AI Defense solutions. Some repositories are believed to belong to Cisco’s clients, potentially exposing sensitive data from sectors like banking, BPO, and government agencies. Cisco’s security teams responded quickly by isolating affected systems, resetting credentials, and rebuilding compromised machines. While containment efforts are ongoing, no official public statement has been released. Investigations suggest multiple threat actors may be involved, with links to the TeamPCP group, raising concerns about potential follow-on attacks.