
Obsidian Security Status
Real-time updates of Obsidian Security issues and outages
Obsidian Security status is Operational
Obsidian Security Security Advisory
You're checking on Obsidian Security - but is your own site converting?
Outages aren't the only thing that costs you visitors.
Get a visual audit that shows exactly where your site loses conversions.
Free, takes 2 minutes.
Active Incidents
No active incidents
Recently Resolved Incidents
Security Advisory: CloudSEK Disclosure — TeamPCP / Trivy Supply Chain Campaign
Published: August 13, 2026 Status: Resolved — no customer impact Customer action required: None
Summary
Obsidian Security is aware of the CloudSEK disclosure regarding the TeamPCP supply chain campaign, which targeted CI/CD pipelines and AI infrastructure beginning in March 2026 and named 2,500+ affected companies.
Obsidian is listed among them. The data published by CloudSEK corresponds to the original Trivy-based campaign that affected our CI/CD systems in mid-March 2026 — an incident we detected at the time, fully investigated, and remediated.
No customer data was exposed at any time. A limited set of Obsidian internal secrets and CI/CD configurations were exposed. The secrets were all unusable in the hands of a third party outside owing to our defense-in-depth protections and swift incident response. All were revoked and rotated in March 2026, and we confirmed that none were used to make any unauthorized access.
What Happened
Mid-March 2026 — Original incident
- Our CI/CD systems were impacted by the Trivy supply chain campaign.
- Some internal secrets and CI/CD configuration were potentially exposed.
- We detected the activity immediately and initiated an incident response.
Our findings:
- No customer data or customer secrets were affected.
- Any exfiltrated secrets were unusable on their own due to our defense-in-depth posture.
- No unauthorized access occurred.
Remediation completed at the time:
- Revoked and rotated all secrets used in the CI/CD pipeline.
- Hardened how our CI/CD pipeline pulls in open-source dependencies and implemented restrictions
August 2026 — CloudSEK publication
CloudSEK apparently obtained and published data from the Trivy campaign, listing 2,500+ impacted companies including Obsidian.
Our response:
- Engaged directly with CloudSEK and obtained the full incident report, including raw log files.
- Confirmed the published data originates entirely from the mid-March 2026 incident — there is no new or additional exposure.
- Reconfirmed that every internal secret appearing in the report had already been rotated in March 2026.
- Verified that none of the exposed secrets were used in any access attempt. Any such attempt would have failed given our layered controls.
- Re-evaluating our disclosure criteria
Why We Did Not Disclose Earlier
Obsidian is continuously targeted, as are all security vendors. We assessed the March 2026 incident against our disclosure criteria and determined that no customer sensitive information was exfiltrated and no customer environment was affected. The incident was contained, remediated, and closed. We are publishing now because the CloudSEK report has brought the underlying data into public view, and we want customers to have an accurate account of what it does and does not represent. We are re-evaluating our disclosure criteria. We remain committed to earning our customers’ trust through transparency, and in the future we anticipate releasing more information about attacks that exfiltrate data, even if we do not consider the data to be sensitive.
Current Status
We have found no new evidence of unauthorized access and have had no incidents reported. We continue to monitor and will provide updates if our assessment changes.
Contact
Customers with questions are welcome to reach out to their Obsidian account team or our support team directly at [email protected]. We are happy to schedule a call to walk through the details of this advisory.
Obsidian Security Outage Survival Guide
Obsidian Security Components
Obsidian Security Platform Services
Admin Portal and UI
Admin Authentication & SSO
Connections (SaaS Applications)
Action Policies
Reporting
Workflow Integrations
API
Obsidian Security Posture Management
Obsidian Security Threat Management
Obsidian Security Integration Management
Obsidian Security Extend
Obsidian Security Security Advisory
Security Advisory: CloudSEK Disclosure — TeamPCP / Trivy Supply Chain Campaign
Published: August 13, 2026 Status: Resolved — no customer impact Customer action required: None
Summary
Obsidian Security is aware of the CloudSEK disclosure regarding the TeamPCP supply chain campaign, which targeted CI/CD pipelines and AI infrastructure beginning in March 2026 and named 2,500+ affected companies.
Obsidian is listed among them. The data published by CloudSEK corresponds to the original Trivy-based campaign that affected our CI/CD systems in mid-March 2026 — an incident we detected at the time, fully investigated, and remediated.
No customer data was exposed at any time. A limited set of Obsidian internal secrets and CI/CD configurations were exposed. The secrets were all unusable in the hands of a third party outside owing to our defense-in-depth protections and swift incident response. All were revoked and rotated in March 2026, and we confirmed that none were used to make any unauthorized access.
What Happened
Mid-March 2026 — Original incident
- Our CI/CD systems were impacted by the Trivy supply chain campaign.
- Some internal secrets and CI/CD configuration were potentially exposed.
- We detected the activity immediately and initiated an incident response.
Our findings:
- No customer data or customer secrets were affected.
- Any exfiltrated secrets were unusable on their own due to our defense-in-depth posture.
- No unauthorized access occurred.
Remediation completed at the time:
- Revoked and rotated all secrets used in the CI/CD pipeline.
- Hardened how our CI/CD pipeline pulls in open-source dependencies and implemented restrictions
August 2026 — CloudSEK publication
CloudSEK apparently obtained and published data from the Trivy campaign, listing 2,500+ impacted companies including Obsidian.
Our response:
- Engaged directly with CloudSEK and obtained the full incident report, including raw log files.
- Confirmed the published data originates entirely from the mid-March 2026 incident — there is no new or additional exposure.
- Reconfirmed that every internal secret appearing in the report had already been rotated in March 2026.
- Verified that none of the exposed secrets were used in any access attempt. Any such attempt would have failed given our layered controls.
- Re-evaluating our disclosure criteria
Why We Did Not Disclose Earlier
Obsidian is continuously targeted, as are all security vendors. We assessed the March 2026 incident against our disclosure criteria and determined that no customer sensitive information was exfiltrated and no customer environment was affected. The incident was contained, remediated, and closed. We are publishing now because the CloudSEK report has brought the underlying data into public view, and we want customers to have an accurate account of what it does and does not represent. We are re-evaluating our disclosure criteria. We remain committed to earning our customers’ trust through transparency, and in the future we anticipate releasing more information about attacks that exfiltrate data, even if we do not consider the data to be sensitive.
Current Status
We have found no new evidence of unauthorized access and have had no incidents reported. We continue to monitor and will provide updates if our assessment changes.
Contact
Customers with questions are welcome to reach out to their Obsidian account team or our support team directly at [email protected]. We are happy to schedule a call to walk through the details of this advisory.