Cisco source code stolen in Trivy-linked dev environment breach
2026-03-31T19:23:31Z•d50a0363a33760214b73795909fd95231613c1ff159bf18777b9ee68bcab59d9
active-exploitationcisacitrixcredential-theftcve-2026-3055data-breachf5-big-ipforticlient-emsfortinethealthcarelateral-movementmacosmalwarenpm-compromisepatchingremote-access-trojanroadk1llsecurity-mitigationsource-code-exposuresupply-chainwebshells
What happened
Multiple high-impact incidents reported across enterprise and open-source ecosystems. Cisco was breached after attackers used credentials stolen in the recent Trivy supply-chain compromise to access an internal development environment and steal source code (including customer code). The popular Axios npm package account was hijacked to push cross‑platform remote access trojans. A critical Citrix NetScaler memory vulnerability (CVE-2026-3055) is being actively exploited and CISA has ordered federal agencies to patch; related Citrix exploitation activity is ongoing. Separately, F5 reclassified a
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- d50a0363a33760214b73795909fd95231613c1ff159bf18777b9ee68bcab59d9
- Enrichment time
- 2026-03-31T19:23:31Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.