Case Study: Aqua Security strengthens CI/CD supply chain security with Reco

A Reco Case Study

Preview of the Aqua Security Case Study

Aqua Security detects supply chain risk with Reco after 500,000 credentials were stolen

Aqua Security faced a catastrophic software supply chain attack after a threat actor exploited a misconfigured CI/CD workflow in their Trivy vulnerability scanner. This initial breach led to the compromise of thousands of downstream pipelines and the exfiltration of approximately 500,000 credentials, impacting multiple ecosystems including GitHub Actions, Docker Hub, npm, and PyPI.

Reco proactively conducted a threat hunt across monitored GitHub organizations following the public disclosure of the vulnerability. While no direct compromise was found, Reco identified and flagged the same type of over-privileged credential configuration that enabled the attack. The vendor deployed a new posture policy to detect such high-risk tokens and is expanding its GitHub detection coverage to surface dangerous workflow configurations and anomalous credential usage, helping to prevent future attacks of this class.


View this case study…

Reco

21 Case Studies