← Back to Feed

From CI/CD to Cloud Data: How Shai Hulud Persistence Leads to Redshift Breach

June 26, 2026 · Fortinet Threat Research · Severity: MEDIUM

This article details how a threat actor linked to Shai Hulud compromised a CI/CD pipeline to steal Jenkins credentials, then escalated privileges in AWS and breached a Redshift database. The activity was detected by FortiCNAPP, highlighting the risks of CI/CD to cloud data security.

See how Shai Hulud-linked CI/CD compromise exposed Jenkins credentials, enabled AWS escalation, and led to Redshift breach activity detected by FortiCNAPP

      

Key Takeaways

  • Shai Hulud-linked CI/CD compromise exposed Jenkins credentials for initial access.
  • Attackers escalated privileges in AWS and moved to Redshift data stores.
  • FortiCNAPP detected the breach activity across cloud and CI/CD pipelines.
☕ Buy a Coffee