Reco
21 Case Studies
A Reco Case Study
Aqua Security faced a catastrophic software supply chain attack after a threat actor exploited a misconfigured CI/CD workflow in their Trivy vulnerability scanner. This initial breach led to the compromise of thousands of downstream pipelines and the exfiltration of approximately 500,000 credentials, impacting multiple ecosystems including GitHub Actions, Docker Hub, npm, and PyPI.
Reco proactively conducted a threat hunt across monitored GitHub organizations following the public disclosure of the vulnerability. While no direct compromise was found, Reco identified and flagged the same type of over-privileged credential configuration that enabled the attack. The vendor deployed a new posture policy to detect such high-risk tokens and is expanding its GitHub detection coverage to surface dangerous workflow configurations and anomalous credential usage, helping to prevent future attacks of this class.