Cisco logo
– Ben Wodecki/SDxCentral

Cisco source code including AI codebases were exposed in a more modern type of cybersecurity breach against the network vendor.

According to Bleeding Computer, Cisco’s development environment was targeted as part of an ongoing supply chain brigade via a malicious GitHub automation plugin. Credentials and data were compromised in the attack, affecting numerous devices such as several developer and lab workstations, while more than 300 of Cisco’s GitHub repositories were cloned, including source code for its AI Assistants, AI Defense, and various unreleased AI products.

Amazon Web Services (AWS) keys were also breached and subsequently used to carry out unauthorized actions across a limited number of Cisco AWS accounts. According to the report, Cisco has contained the affected systems, initiated re-imaging procedures, and begun extensive credential rotation, with the firm yet to publicly comment on the situation.

The attack was conducted as part of a Trivy-based campaign uncovered in March. The vulnerability scanner – designed to operate across containers, Kubernetes environments, code repositories, and cloud infrastructure – was compromised in a supply chain attack by the TeamPCP threat group, which distributed credential-stealing malware through official releases and GitHub Actions.

While Cisco breaches often center around hardware and legacy vulnerabilities, a 2024 attack saw an actor download certain files from a developer-facing environment belonging to Cisco. Source code, API tokens, certificates, and internal documents were swiped in the breach, affecting a limited set of CX Professional Services.