Executive Summary
In March 2026, Cisco's internal development environment was breached through a sophisticated supply chain attack involving the Trivy vulnerability scanner. Threat actors, identified as TeamPCP, compromised Trivy's GitHub Actions pipeline, injecting credential-stealing malware into official releases. This allowed them to harvest credentials from organizations using Trivy, including Cisco. Leveraging these stolen credentials, the attackers infiltrated Cisco's build systems and developer workstations, exfiltrating over 300 private GitHub repositories containing source code for AI-powered products and unreleased items. Additionally, customer repositories belonging to banks, business process outsourcing firms, and U.S. government agencies were among those exfiltrated. AWS keys were also stolen and used for unauthorized activities across Cisco's cloud accounts. Cisco has since isolated affected systems, initiated reimaging, and is performing wide-scale credential rotation to contain the breach. (bleepingcomputer.com)
This incident underscores the escalating threat posed by supply chain attacks, where compromising a widely-used tool can have cascading effects across multiple organizations. The breach highlights the critical need for organizations to scrutinize the security of third-party tools integrated into their development pipelines and to implement robust monitoring and incident response strategies to detect and mitigate such sophisticated attacks.
Why This Matters Now
The Cisco breach exemplifies the growing sophistication of supply chain attacks, emphasizing the urgent need for organizations to reassess the security of their development tools and implement stringent monitoring and response mechanisms to safeguard against similar threats.
Attack Path Analysis
The attack began with the compromise of Aqua Security's Trivy security scanner, allowing attackers to inject malicious code into its releases. This led to the theft of credentials from organizations using Trivy in their CI/CD pipelines. Using these stolen credentials, attackers escalated privileges within affected environments, gaining unauthorized access to sensitive systems. They then moved laterally across networks, accessing additional resources and systems. Establishing command and control channels, the attackers maintained persistent access to compromised environments. Finally, they exfiltrated sensitive data, including over 300 private GitHub repositories from Cisco, containing source code for AI-powered products and customer information.
Kill Chain Progression
Initial Compromise
Description
Attackers compromised Aqua Security's Trivy security scanner by injecting malicious code into its releases, leading to the distribution of infected versions to users.
Related CVEs
CVE-2026-33634
CVSS 8.8Compromised credentials allowed attackers to publish malicious versions of Trivy components, leading to potential credential theft and unauthorized access.
Affected Products:
Aqua Security Trivy – 0.69.4
Aqua Security trivy-action – 0.0.1, 0.34.2
Aqua Security setup-trivy – 0.2.0, 0.2.6
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Compromise Software Supply Chain
Valid Accounts
Credentials in Files
Web Protocols
Automated Exfiltration
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Change Control Processes
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Network and Environment Segmentation
Control ID: Pillar 3
NIS2 Directive – Supply Chain Security
Control ID: Article 21
ISO/IEC 27001 – Management of Technical Vulnerabilities
Control ID: A.12.6.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
Direct supply chain compromise via Trivy vulnerability affecting CI/CD pipelines, source code repositories, and development environments across software companies.
Information Technology/IT
Critical exposure through compromised GitHub Actions, Docker registries, and cloud infrastructure affecting managed services and client environments.
Financial Services
High-value target for credential monetization with stolen bank repositories and customer data creating regulatory compliance violations and breach notifications.
Government Administration
Federal agencies face KEV compliance deadlines while attackers target government repositories including FBI, DHS, NASA creating national security implications.
Sources
- TeamPCP Supply Chain Campaign: Update 007 - Cisco Source Code Stolen via Trivy-Linked Breach, Google GTIG Tracks TeamPCP as UNC6780, and CISA KEV Deadline Arrives with No Standalone Advisory, (Wed, Apr 8th)https://isc.sans.edu/diary/rss/32880Verified
- Cisco Source Code Stolen in Trivy Supply Chain Attackhttps://www.safestate.com/post/cisco-source-code-stolen-in-trivy-supply-chain-attackVerified
- Trivy Supply Chain Compromise Leads to Cisco Dev Environment Breachhttps://www.ampcuscyber.com/shadowopsintel/trivy-supply-chain-compromise-leads-to-cisco-dev-environment-breach/Verified
- CVE-2026-33634 - Trivy ecosystem supply chain briefly compromisedhttps://nvd.nist.gov/vuln/detail/CVE-2026-33634Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it could have limited the attacker's ability to escalate privileges, move laterally, and exfiltrate sensitive data by enforcing strict segmentation and identity-aware controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF may not have prevented the initial compromise of Trivy, it could have limited the subsequent unauthorized access within the cloud environment.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation could have limited the attacker's ability to escalate privileges by enforcing strict access controls and minimizing trust relationships.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security could have restricted the attacker's lateral movement by monitoring and controlling internal traffic flows.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control could have detected and constrained unauthorized command and control communications.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement could have limited the attacker's ability to exfiltrate sensitive data by controlling outbound traffic.
While Aviatrix CNSF may not have entirely prevented the impact, it could have significantly reduced the scope of data exfiltration and limited the exposure of sensitive information.
Impact at a Glance
Affected Business Functions
- Software Development
- Product Management
- Customer Support
Estimated downtime: 14 days
Estimated loss: $5,000,000
Source code for AI-powered products, including unreleased items; customer repositories belonging to banks, business process outsourcing firms, and US government agencies; AWS keys used for unauthorized activities.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to enforce least privilege access and limit lateral movement within networks.
- • Deploy East-West Traffic Security controls to monitor and restrict internal traffic, preventing unauthorized lateral movement.
- • Utilize Egress Security & Policy Enforcement to control outbound traffic and detect data exfiltration attempts.
- • Establish Multicloud Visibility & Control to gain comprehensive insights into cloud environments and detect anomalies.
- • Apply Inline IPS (Suricata) to inspect and block malicious traffic patterns, enhancing threat detection capabilities.



