DiscoverCybersecurity TodayCisco Breached: Source Code Stolen - Cybersecurity Today
Cisco Breached: Source Code Stolen - Cybersecurity Today

Cisco Breached: Source Code Stolen - Cybersecurity Today

Update: 2026-04-01
Share

Digest

This podcast covers several significant cybersecurity incidents and emerging threats. Cisco's development environment was breached via stolen credentials from a previous supply chain attack, leading to the theft of AI product source code. The popular JavaScript library Axios was also compromised through a supply chain attack, with malicious versions distributed via the NPM registry. Critical vulnerabilities are being actively exploited in Fortinet's FortiClient EMS platform (CVE 2026-21-643) and Citrix NetScaler ADC/Gateway (CVE 2026-3055), highlighting ongoing risks with these widely used products. Additionally, Anthropic accidentally leaked details about a powerful new AI model, Claude Mythos, capable of rapid vulnerability exploitation, raising concerns about AI's impact on cybersecurity. Finally, a compliance startup, Delve, faces accusations of helping clients fabricate audit evidence, undermining the integrity of compliance frameworks.

Outlines

00:00:00
Major Cybersecurity Breaches and Vulnerabilities

This section details critical security incidents including the breach of Cisco's development environment through supply chain attack credentials, the compromise of the Axios JavaScript library via a supply chain attack, and the active exploitation of severe vulnerabilities in Fortinet's FortiClient EMS (CVE 2026-21-643) and Citrix NetScaler (CVE 2026-3055).

00:08:22
Emerging AI Risks and Compliance Scandals

This part discusses the accidental leak of Anthropic's advanced AI model, Claude Mythos, which poses risks due to its rapid vulnerability exploitation capabilities. It also covers the compliance scandal involving Delve, accused of helping clients falsify audit evidence for SOC2 and ISO 27001 certifications.

Keywords

Supply Chain Attack


An attack where threat actors compromise a trusted software vendor or product to distribute malware or steal data. This can impact numerous downstream users, as seen with the Trivy and Axios incidents.

SQL Injection


A code injection technique used to attack data-driven applications, where malicious SQL statements are inserted into an entry field for execution. This is a long-standing vulnerability class, as demonstrated by the Fortinet breach.

CVE 2026-3055


A critical vulnerability in Citrix NetScaler ADC and Gateway with a severity score of 9.3. It's being actively exploited, and CISA has added it to their known exploited vulnerabilities catalog, requiring urgent remediation.

Claude Mythos


A new, advanced AI model developed by Anthropic, reportedly capable of reasoning, coding, and cybersecurity tasks, including rapid vulnerability exploitation. Its accidental leak has raised concerns about AI's potential impact on cybersecurity.

SOC2 and ISO 27001


Compliance frameworks that help organizations manage sensitive company information. Delve is accused of helping clients falsify evidence to achieve these certifications, undermining their security value.

Fortinet Vulnerability


Critical SQL injection vulnerability (CVE 2026-21-643) in FortiClient EMS platform, allowing arbitrary code execution and actively exploited by attackers.

Citrix NetScaler Vulnerability


Critical vulnerability (CVE 2026-3055) in NetScaler ADC and Gateway, actively exploited by threat actors, following a pattern of past critical flaws.

Q&A

  • How did the attackers breach Cisco's development environment?

    Threat actors used credentials stolen in a previous Trivy supply chain attack. They leveraged a malicious GitHub action to access Cisco's internal development environment, cloning over 300 repositories.

  • What makes the Axios supply chain attack particularly concerning?

    The attackers demonstrated patience by first establishing trust with a clean package before pushing malicious versions. The malware was hidden in a fake dependency, designed to bypass traditional code reviews and security checks.

  • What is the significance of CVE 2026-21-643 affecting Fortinet?

    This is a critical SQL injection vulnerability in Fortinet's FortiClient EMS platform that is being actively exploited. It allows unauthenticated attackers to execute arbitrary code, and Fortinet has a history of such exploitable flaws.

  • What is the "Citrix bleed" and why is it relevant now?

    "Citrix bleed" refers to a critical vulnerability in Citrix NetScaler that was exploited in 2023. A similar critical vulnerability (CVE 2026-3055) is now being exploited, raising concerns about a repeat of past breaches.

  • What are the main concerns surrounding Anthropic's Claude Mythos AI model?

    The model is described as highly capable in reasoning, coding, and cybersecurity, with the potential to exploit vulnerabilities much faster than defenders can respond. Its leak highlights the escalating risks posed by advanced AI.

  • What is the core issue with the Delve compliance scandal?

    Delve is accused of facilitating fake compliance by helping clients fabricate audit evidence and working with unqualified auditors. This undermines the integrity of compliance frameworks like SOC2 and ISO 27001.

Show Notes

Cisco Source Code Stolen in Trivy Fallout, Axios Supply Chain Attack, and Active Exploitation of Fortinet and Citrix Flaws

David Shipley reports multiple major security incidents: attackers used credentials stolen in the Trivy supply-chain attack via a malicious GitHub action to breach Cisco's internal development environment, clone 300+ GitHub repos, steal source code (including AI products) and AWS keys, and impact customer-related code; Cisco contained the breach, re-imaged systems, and rotated credentials. A separate supply-chain attack hit the widely used JavaScript library Axios after its maintainer account was compromised, pushing poisoned NPM versions that installed a dropper/RAT via a fake dependency; users are told to downgrade affected versions, remove the dependency, rotate credentials, and review CI/CD logs. Active exploitation is confirmed for a Fortinet FortiClient EMS SQL injection (CVE-2026-21643) and for critical Citrix NetScaler flaws (CVE-2026-3055, possibly alongside CVE-2026-4368). Anthropic accidentally exposed details of a new model, "Code Mythos," described as highly capable in reasoning, coding, and cybersecurity. Finally, TechCrunch reports escalating allegations that compliance startup Delve helped fabricate audit evidence and worked with weak auditors. The episode also marks show episode 1,500.

00:00 Headlines and Sponsor
00:54 Cisco Trivy Breach
02:28 Axios NPM Attack
04:12 Fortinet SQLi Exploited
06:24 Citrix Bleed Returns
08:05 Anthropic Model Leak
10:24 Fake Compliance Scandal
12:30 Episode 1500 Milestone
14:03 Sponsor Closing Message

Comments 
In Channel
loading

Table of contents

00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Cisco Breached: Source Code Stolen - Cybersecurity Today

Cisco Breached: Source Code Stolen - Cybersecurity Today

David Shipley