CLOUDSEK reported that Team PCP, a threat actor, exfiltrated 78,330 secrets from CI/CD pipelines of 2,186 organizations over five days in March 2026. This incident highlights the vulnerabilities in CI/CD systems as attackers can compromise a trusted open-source project and strategically harvest credentials. Key findings include significant exposure across major CI/CD platforms, with GitLab being the most affected. The stolen credentials included session tokens and API keys that can lead to further breaches.
StepSecurity emphasizes the need for layered security controls to mitigate such risks and offers solutions for runtime monitoring and incident response.