Over 10 years we help companies reach their financial and branding goals. Engitech is a values-driven technology agency dedicated.

Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

The TeamPCP threat group compromised the Trivy GitHub Action, a widely used open-source vulnerability scanner, and used it as a vector to steal credentials from CI/CD pipelines at Cisco and other organizations. Cisco confirmed the theft of source code from over 300 internal repositories, including proprietary AI products and third-party customer code from banks, government agencies, and BPOs; exfiltrated AWS keys were subsequently used against Cisco cloud infrastructure. The incident is not fully contained, and any organization running Trivy, LiteLLM, or Checkmarx KICS in CI/CD pipelines should treat credentials exposed through those pipelines as compromised.

Author

Tech Jacks Solutions