Cypress Security Incident: Status and Response
Blog post from Cypress
Cypress reported that a zero-day vulnerability in its Metabase Cloud analytics instance was exploited on July 31, 2026, allowing an attacker to query a subset of data, including limited business and account information, repository and build metadata, and in some cases tokens or test data. Metabase notified Cypress on August 6, Cypress informed affected organizations on August 7, and the company says it found no evidence of continuing unauthorized access after Metabase patched the flaw, blocked the access method, and invalidated sessions. Cypress rotated affected database credentials and keys, revoked Cypress Cloud GitHub OAuth authorizations as a precaution, audited logs, and hired an independent forensic firm to review the incident. Cypress Cloud test execution and results, record keys, account passwords, payment information, and application code were not affected, while impacted customers were contacted directly. Users are advised to rotate any secrets included in build parameters or recorded test data, replace hardcoded long-lived version-control tokens, review repository access logs from July 31 onward, and remain alert to phishing attempts.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| Secrets Management | 3 | 2,244 | 480 | 132 | -13% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.