Security tooling is granted the broadest read access in most engineering organisations, and it is granted it for good reasons. A scanner that cannot see every repository cannot report on every repository.
Reporting describes stolen credentials associated with the Trivy scanning tool being used to reach Cisco build systems, with more than 300 GitHub repositories cloned, and AWS keys and customer code among the material described.
The Scanner’s Access Is The Union Of Everything
A single team’s credential reaches that team’s code. A scanner’s credential reaches all of it, by design, and typically has no reason to be constrained by branch, project or sensitivity. Its access is the union of every access it was created to inspect.
Compounding it, scanner activity is high-volume and automated by nature. Bulk repository reads are exactly what the tool is supposed to do, so anomaly detection tuned to human behaviour has nothing to fire on.
Secrets Inside The Code Are The Second Breach
Cloned source is a problem in itself. Cloned source containing cloud credentials is a different problem, and the reported presence of AWS keys points at it. Ironically, hard-coded secrets are precisely what a scanner of this type exists to find — which means its access reaches repositories already known to contain them.
Graded medium. The access route and repository count are consistently reported; the downstream impact of any recovered credentials is not established.
Compiled from public reporting, listed below. We have not reviewed the cloned repositories and are not describing customer code. Corrections: corrections@forensicpost.com.
- List of recent data breaches in 2026Bright Defense