Desk live·
ForensicPost
Cloud/Supply chain/File 26-0331

Three Hundred Repositories, Reached With a Scanner’s Credentials

Credentials associated with the Trivy scanning tool were reportedly used to reach Cisco build systems, with around 300 GitHub repositories cloned. The tool that inventories your risk holds access to everything it inventories.

Constructed geometry · not a chart of case data
TargetCisco
ActorUnattributed
D. Kennedy9 min readConfidence: medium1 source reviewed

Security tooling is granted the broadest read access in most engineering organisations, and it is granted it for good reasons. A scanner that cannot see every repository cannot report on every repository.

Reporting describes stolen credentials associated with the Trivy scanning tool being used to reach Cisco build systems, with more than 300 GitHub repositories cloned, and AWS keys and customer code among the material described.

The Scanner’s Access Is The Union Of Everything

A single team’s credential reaches that team’s code. A scanner’s credential reaches all of it, by design, and typically has no reason to be constrained by branch, project or sensitivity. Its access is the union of every access it was created to inspect.

Compounding it, scanner activity is high-volume and automated by nature. Bulk repository reads are exactly what the tool is supposed to do, so anomaly detection tuned to human behaviour has nothing to fire on.

Secrets Inside The Code Are The Second Breach

Cloned source is a problem in itself. Cloned source containing cloud credentials is a different problem, and the reported presence of AWS keys points at it. Ironically, hard-coded secrets are precisely what a scanner of this type exists to find — which means its access reaches repositories already known to contain them.

Graded medium. The access route and repository count are consistently reported; the downstream impact of any recovered credentials is not established.

How we reported this

Compiled from public reporting, listed below. We have not reviewed the cloned repositories and are not describing customer code. Corrections: corrections@forensicpost.com.

Sources
  1. List of recent data breaches in 2026Bright Defense
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary