TeamPCP Supply Chain Campaign: Update 007 - Cisco Source Code Stolen via Trivy-Linked Breach, Google GTIG Tracks TeamPCP as UNC6780, and CISA KEV Deadline Arrives with No Standalone Advisory, (Wed, Apr 8th)
2026-04-08T19:23:48Z•26cbf66924771e1e704f30b453996276d7e20bdca6f10f07bd29ea3589bf319c
CERT-EUCISA KEVCVE-2025-30208CiscoGTIGMandiantSaaS compromiseShinyHuntersSportradarTeamPCPTrivyUNC6780Vitehoneypot fingerprintingphishing open redirectsource code theftsupply chainsupply-chain compromisevulnerability exploitationwebshells
What happened
SANS ISC digest (Apr 3–8, 2026) highlights an ongoing TeamPCP supply‑chain campaign: Cisco source code was exfiltrated via a Trivy‑linked breach, Google’s GTIG tracks the cluster as UNC6780, and CISA’s KEV deadline passed without a standalone advisory. Mandiant and other responders report widespread impact (1,000+ compromised SaaS environments); CERT‑EU confirmed an EC cloud breach; Sportradar and ShinyHunters disclosures/credential sharing surfaced. Related coverage includes increased honeypot fingerprinting, webshell usage and weak/backdoor credentials for persistence, active misuse of open‑
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 26cbf66924771e1e704f30b453996276d7e20bdca6f10f07bd29ea3589bf319c
- Enrichment time
- 2026-04-08T19:23:48Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.