{
"vendor": "Obsidian Security",
"slug": "obsidian-security",
"platform": "statuspage",
"status_url": "https://status.obsidiansecurity.com",
"last_checked": "2026-09-16T12:28:20Z",
"last_state": "ok",
"history_backfilled": true,
"first_watched": "2026-09-04T07:06:16Z",
"incidents": [
{
"body": "Security Advisory: CloudSEK Disclosure \u2014 TeamPCP / Trivy Supply Chain Campaign\n\nPublished: August 13, 2026 \nStatus: Resolved \u2014 no customer impact \nCustomer action required: None\n\nSummary\n\nObsidian Security is aware of the CloudSEK disclosure regarding the TeamPCP supply chain campaign, which targeted CI/CD pipelines and AI infrastructure beginning in March 2026 and named 2,500+ affected companies.\n\nObsidian is listed among them. The data published by CloudSEK corresponds to the original Trivy-based campaign that affected our CI/CD systems in mid-March 2026 \u2014 an incident we detected at the time, fully investigated, and remediated.\n\nNo customer data was exposed at any time. A limited set of Obsidian internal secrets and CI/CD configurations were exposed. The secrets were all unusable in the hands of a third party outside owing to our defense-in-depth protections and swift incident response. All were revoked and rotated in March 2026, and we confirmed that none were used to make any unauthorized access.\n\nWhat Happened\n\nMid-March 2026 \u2014 Original incident\n- Our CI/CD systems were impacted by the Trivy supply chain campaign.\n- Some internal secrets and CI/CD configuration were potentially exposed.\n- We detected the activity immediately and initiated an incident response.\n\nOur findings:\n- No customer data or customer secrets were affected.\n- Any exfiltrated secrets were unusable on their own due to our defense-in-depth posture.\n- No unauthorized access occurred.\n\nRemediation completed at the time:\n- Revoked and rotated all secrets used in the CI/CD pipeline.\n- Hardened how our CI/CD pipeline pulls in open-source dependencies and implemented restrictions \n\nAugust 2026 \u2014 CloudSEK publication\n\nCloudSEK apparently obtained and published data from the Trivy campaign, listing 2,500+ impacted companies including Obsidian.\n\nOur response:\n- Engaged directly with CloudSEK and obtained the full incident report, including raw log files.\n- Confirmed the published data originates entirely from the mid-March 2026 incident \u2014 there is no new or additional exposure.\n- Reconfirmed that every internal secret appearing in the report had already been rotated in March 2026.\n- Verified that none of the exposed secrets were used in any access attempt. Any such attempt would have failed given our layered controls.\n- Re-evaluating our disclosure criteria\n\nWhy We Did Not Disclose Earlier \n\nObsidian is continuously targeted, as are all security vendors. We assessed the March 2026 incident against our disclosure criteria and determined that no customer sensitive information was exfiltrated and no customer environment was affected. The incident was contained, remediated, and closed. We are publishing now because the CloudSEK report has brought the underlying data into public view, and we want customers to have an accurate account of what it does and does not represent. We are re-evaluating our disclosure criteria. We remain committed to earning our customers\u2019 trust through transparency, and in the future we anticipate releasing more information about attacks that exfiltrate data, even if we do not consider the data to be sensitive.  \n\nCurrent Status\n\nWe have found no new evidence of unauthorized access and have had no incidents reported. We continue to monitor and will provide updates if our assessment changes.\n\nContact\n\nCustomers with questions are welcome to reach out to their Obsidian account team or our support team directly at support@obsidiansecurity.com. We are happy to schedule a call to walk through the details of this advisory.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "none",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-08-14T13:09:47.000-07:00",
"resolved_inferred": false,
"started_at": "2026-08-14T13:09:47.000-07:00",
"state": "resolved",
"title": "Security Advisory: CloudSEK Disclosure - TeamPCP / Trivy Supply Chain Campaign",
"updated_at": "2026-08-14T15:21:32.500-07:00",
"url": "https://stspg.io/sqpm06d9604h"
},
{
"body": "This issue is resolved.\n\nWe have verified that the issue affecting a subset of identity-centric detections and related alert notifications within the Obsidian US environment has been fully mitigated.\n\nAlerting is operating as expected, and this incident is now resolved.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-06-12T18:08:17.521-07:00",
"resolved_inferred": false,
"started_at": "2026-06-12T09:31:11.348-07:00",
"state": "resolved",
"title": "[US Region] - Delayed Identity-Centric Alerts",
"updated_at": "2026-06-12T18:08:17.539-07:00",
"url": "https://stspg.io/58xkd39g81m6"
},
{
"body": "This issue is resolved.  We have taken mitigating actions to restore processing, and batch (non-real-time) alerts are now processing normally.  Alerting workflows impacted by this issue have resumed as expected, and we are no longer seeing ongoing delay related to this event.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-06-09T08:29:15.732-07:00",
"resolved_inferred": false,
"started_at": "2026-06-09T07:38:01.613-07:00",
"state": "resolved",
"title": "[US Region] - Subset of Alerts Delayed",
"updated_at": "2026-06-09T08:29:15.752-07:00",
"url": "https://stspg.io/54v7sxrr6kmy"
},
{
"body": "We have verified that the issue affecting a subset of threat detections in US region environments has been fully mitigated.  Alerting is operating as expected, and this incident is now resolved.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-05-27T07:25:30.142-07:00",
"resolved_inferred": false,
"started_at": "2026-05-27T05:40:10.498-07:00",
"state": "resolved",
"title": "[US Region] - Subset of threat detections delayed",
"updated_at": "2026-05-27T07:25:30.158-07:00",
"url": "https://stspg.io/v80fywdqw0dt"
},
{
"body": "This incident has been resolved. Monitoring has confirmed that service has returned to normal operation, and threat detections are processing as expected.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-05-15T14:03:38.616-07:00",
"resolved_inferred": false,
"started_at": "2026-05-15T08:10:31.306-07:00",
"state": "resolved",
"title": "Subset of Detections Delayed",
"updated_at": "2026-05-15T14:03:38.634-07:00",
"url": "https://stspg.io/swq65zsnr06v"
},
{
"body": "A fix to address an issue resulting in detection and alerting delays for a subset of threat detections has been deployed.  Telemetry and post fix validation confirm a return to normal service operation.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-05-15T07:47:18.131-07:00",
"resolved_inferred": false,
"started_at": "2026-05-15T07:05:39.868-07:00",
"state": "resolved",
"title": "Subset of detections delayed",
"updated_at": "2026-05-15T07:47:18.148-07:00",
"url": "https://stspg.io/6phvkn249r5r"
},
{
"body": "A fix to address the issue of \"Not Found\" errors being displayed upon attempt to load Obsidian Environments has been released, and telemetry and post fix validation confirm a return to normal service operation.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "critical",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-03-11T07:34:44.278-07:00",
"resolved_inferred": false,
"started_at": "2026-03-11T07:05:17.368-07:00",
"state": "resolved",
"title": "Not Found  ( HTTP-404) Errors when attempting to access Obsidian Environment",
"updated_at": "2026-03-11T07:34:44.294-07:00",
"url": "https://stspg.io/3x5d3hl0nhys"
},
{
"body": "This incident has been resolved.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "none",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-03-11T04:47:43.535-07:00",
"resolved_inferred": false,
"started_at": "2026-03-11T00:51:55.282-07:00",
"state": "resolved",
"title": "Activity timeline delay",
"updated_at": "2026-03-11T04:47:43.549-07:00",
"url": "https://stspg.io/plbk9hh7jt5l"
},
{
"body": "We have fully resolved the issue that was impacting the US environment. System performance and operation have returned to normal levels, and all services are functioning as expected.\n\nOur team will continue to monitor the environment closely, but no further impact is anticipated at this time.\n\nThank you for your patience while we work to restore normal operation.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-02-09T14:50:54.923-08:00",
"resolved_inferred": false,
"started_at": "2026-02-09T13:06:09.433-08:00",
"state": "resolved",
"title": "Intermittent failures when loading Obsidian admin console",
"updated_at": "2026-02-09T14:50:54.941-08:00",
"url": "https://stspg.io/zs2dg2g6jqbf"
},
{
"body": "We see US region got UI response slowness. Team identified it related to a backend issue. A fix was applied. The issue is resolved at 11:20AM",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-02-09T11:00:00.000-08:00",
"resolved_inferred": false,
"started_at": "2026-02-09T11:00:00.000-08:00",
"state": "resolved",
"title": "Web UI slowness for US region",
"updated_at": "2026-02-09T11:24:02.759-08:00",
"url": "https://stspg.io/tskvby118zbg"
},
{
"body": "After monitoring system performance and fully confirming the previously deployed fix to be effective, we are now marking this incident as resolved.   All affected functionality has been fully restored, and customers should no longer encounter \"An error has occurred\" when loading these modules.\n\nThank you for your patience while we worked through and resolved this incident.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "critical",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2026-01-05T05:04:27.000-08:00",
"resolved_inferred": false,
"started_at": "2026-01-04T17:44:20.000-08:00",
"state": "resolved",
"title": "Service partially down(threat, activity) for US region",
"updated_at": "2026-01-05T05:04:45.815-08:00",
"url": "https://stspg.io/wrzl1w0w4yqn"
},
{
"body": "This incident has been resolved.  Our monitoring is no longer showing elevated error rates and all components across the Obsidian platform are fully operational.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-12-05T01:22:52.888-08:00",
"resolved_inferred": false,
"started_at": "2025-12-05T01:07:25.990-08:00",
"state": "resolved",
"title": "Obsidian Administration UI Access - Cloudflare Outage",
"updated_at": "2025-12-05T01:22:52.905-08:00",
"url": "https://stspg.io/bxbdjhxbwrs6"
},
{
"body": "This incident has been resolved.  Our monitoring is no longer showing elevated error rates and all components across the Obsidian platform are fully operational.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "major",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-11-18T10:27:50.151-08:00",
"resolved_inferred": false,
"started_at": "2025-11-18T04:16:42.188-08:00",
"state": "resolved",
"title": "Obsidian Administration UI Access - Cloudflare Outage",
"updated_at": "2025-11-18T10:27:50.166-08:00",
"url": "https://stspg.io/qh0224t4gq0v"
},
{
"body": "This incident has been resolved. We have released a permanent fix in the Obsidian Browser Extension version ver. 1.13.4, which is now rolling out via auto\u2011update.\n\n\n<b>What to expect: </b>\nThe updated extension will install automatically as it propagates to users.\n\n\n<b>Next steps: </b>\nIf you previously disabled Phishing Detections as a workaround, you may re\u2011enable it once your environment has received version 1.13.4.\n\n\n<b>Scope: </b>\nNo other Browser Extension capabilities were affected.\n\n\n<b>Support:</b>\nFor help confirming rollout status or re\u2011enabling Phishing Detections, contact Obsidian Support at support@obsidiansecurity.com or your Technical Account Manager.\n\nThank you for your patience while we worked to resolve this issue.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-11-13T06:56:09.934-08:00",
"resolved_inferred": false,
"started_at": "2025-11-12T11:12:11.815-08:00",
"state": "resolved",
"title": "Obsidian Browser Extension ver. 1.13.x Page Unresponsive Errors",
"updated_at": "2025-11-13T06:56:09.951-08:00",
"url": "https://stspg.io/b9ch14083m81"
},
{
"body": "This issue has been resolved.  A fix addressing the underlying issue was implemented and authentication services have returned to normal operation.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "critical",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-11-06T11:39:48.451-08:00",
"resolved_inferred": false,
"started_at": "2025-11-06T11:03:14.703-08:00",
"state": "resolved",
"title": "Errors when authenticating to the Obsidian admin portal",
"updated_at": "2025-11-06T11:39:48.477-08:00",
"url": "https://stspg.io/bjfm9ys95j3l"
},
{
"body": "The issue has been resolved and impacted Salesforce posture rules now reflect the correct status.  We appreciate your patience and understanding during this time, and if you experience any further issues, please do not hesitate to reach out.",
"first_seen": "2026-09-04T07:06:16Z",
"impact": "minor",
"last_seen": "2026-09-16T12:28:20Z",
"resolved_at": "2025-08-28T16:05:48.445-07:00",
"resolved_inferred": false,
"started_at": "2025-08-28T09:06:43.000-07:00",
"state": "resolved",
"title": "Subset of Salesforce posture rule unexpectedly changed to passing",
"updated_at": "2025-08-28T16:05:48.461-07:00",
"url": "https://stspg.io/tz77nglq67lr"
}
]
}