Threat actors used stolen credentials from a security-scanner supply-chain compromise to breach Cisco’s development environment through a malicious GitHub Action, cloning more than 300 repositories, including source code for Cisco’s AI Assistant and AI Defense products. The attackers also stole multiple AWS keys used to access Cisco cloud accounts, and downstream repositories belonging to Cisco customers, including banks, business-process outsourcers, and government agencies, were exposed as a result. Cisco isolated affected systems, began reimaging devices, and rotated credentials broadly in response.