← Back to Feed

From CI/CD to Cloud Data: How Shai Hulud Persistence Leads to Redshift Breach

June 26, 2026 · Fortinet Threat Research · Severity: MEDIUM

A threat actor linked to the Shai Hulud malware campaign compromised a CI/CD pipeline to steal Jenkins credentials, escalating access to AWS and ultimately breaching an Amazon Redshift database. Fortinet's Cloud-Native Application Protection Platform (FortiCNAPP) detected the attack, which began with the exploitation of a Jenkins server to gain initial access. The attackers then abused stolen credentials to move laterally into AWS, where they accessed sensitive data stored in Redshift. The breach highlights the risks of insufficient CI/CD security and credential management, particularly in cloud environments. Organizations using Jenkins, AWS, or Redshift should review access controls, monitor for unusual activity, and implement least-privilege principles. Fortinet's findings underscore how attackers leverage initial access to pivot into critical cloud assets, making early detection and response essential to prevent data exfiltration.

See how Shai Hulud-linked CI/CD compromise exposed Jenkins credentials, enabled AWS escalation, and led to Redshift breach activity detected by FortiCNAPP

      

Key Takeaways

  • From CI/CD to Cloud Data: How Shai Hulud Persistence Leads to Redshift Breach — See how Shai Hulud-linked CI/CD compromise exposed Jenkins credentials, enabled AWS escalation,...
  • AI and LLM usage introduces new attack surfaces, including hallucinated domains and prompt injection risks.
  • Credential theft remains a primary initial-access vector; enforce MFA and monitor for anomalous authentication patterns.
  • Regular security awareness training and layered defenses remain the foundation of any effective cybersecurity program.
☕ Buy a Coffee