Is Obsidian Security down?
Last checked just nowNo incidents right now.
Free · no credit card
Obsidian Security is operational right now. Last checked just now; the most recent incident resolved 30d ago.
Real-time Obsidian Security status, recent outages, and incident history — pulled directly from Obsidian Security's official status page at https://status.obsidiansecurity.com every 5 minutes. Pingoru tracks 13 Obsidian Security services and has captured 1 incident in the last 90 days (100.00% uptime). Get email, Slack, Discord, or webhook alerts the moment Obsidian Security reports a new incident — free for 5 monitors, no credit card.
Recent outages & incidents
Past 90 days- Security Advisory
Timeline · 1 update
- resolved · Aug 14, 2026, 08:09 PM UTC
Security Advisory: CloudSEK Disclosure — TeamPCP / Trivy Supply Chain Campaign Published: August 14, 2026 Status: Resolved - no customer impact Customer action required: None Summary Obsidian Security is aware of the CloudSEK disclosure regarding the TeamPCP supply chain campaign, which targeted CI/CD pipelines and AI infrastructure beginning in March 2026 and named 2,500+ affected companies. Obsidian is listed among them. The data published by CloudSEK corresponds to the original Trivy-based campaign that affected our CI/CD systems in mid-March 2026, an incident we detected at the time, fully investigated, and remediated. No customer data was exposed at any time. A limited set of Obsidian internal secrets and CI/CD configurations were exposed. The secrets were all unusable in the hands of a third party owing to our defense-in-depth protections and swift incident response. All were revoked and rotated in March 2026, and we confirmed none were used to make any unauthorized access. What Happened Mid-March 2026 — Original incident - Our CI/CD systems were impacted by the Trivy supply chain campaign. - Some internal secrets and CI/CD configuration were potentially exposed. - We detected the activity immediately and initiated an incident response. Our findings: - No customer data or customer secrets were affected. - Any exfiltrated secrets were unusable on their own due to our defense-in-depth posture. - No unauthorized access occurred. Remediation completed at the time: - Revoked and rotated all secrets used in the CI/CD pipeline. - Hardened how our CI/CD pipeline pulls in open-source dependencies and implemented restrictions. August 2026 — CloudSEK publication CloudSEK obtained and published data from the Trivy campaign, listing 2,500+ impacted companies including Obsidian. Our response: - Engaged directly with CloudSEK and obtained the full incident report, including raw log files. - Confirmed the published data originates entirely from the mid-March 2026 incident, with no new or additional exposure. - Reconfirmed that every internal secret appearing in the report had already been rotated in March 2026. - Verified that none of the exposed secrets were used in any access attempt. Any such attempt would have failed given our layered controls. - Re-evaluating our disclosure criteria. Why We Did Not Disclose Earlier Obsidian is continuously targeted, as are all security vendors. We assessed the March 2026 incident against our disclosure criteria and determined that no customer sensitive information was exfiltrated and no customer environment was affected. The incident was contained, remediated, and closed. We are publishing now because the CloudSEK report has brought the underlying data into public view, and we want customers to have an accurate account of what it does and does not represent. We are re-evaluating our disclosure criteria, and going forward anticipate releasing more information about attacks that exfiltrate data, even if we do not consider the data to be sensitive. Current Status We have found no new evidence of unauthorized access and have had no incidents reported. We continue to monitor and will provide updates if our assessment changes. Contact Customers with questions are welcome to reach out to their Obsidian account team or our support team directly at [email protected]. We are happy to schedule a call to walk through the details of this advisory.
Latest: Security Advisory: CloudSEK Disclosure — TeamPCP / Trivy Supply Chain Campaign Published: August 14, 2026 Status: Resolved - no customer impact Customer action required: None Summa…
-
- Started Aug 14, 2026, 08:09 PM UTC · Resolved Aug 14, 2026, 08:09 PM UTC · —