home.social

#checkmarx — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #checkmarx, aggregated by home.social.

  1. Bitwarden CLI has been compromised as part of the newly discovered and ongoing Checkmarx supply chain campaign. Bitwarden confirmed the incident and said it stemmed from the compromise of its npm distribution mechanism following the Checkmarx supply chain attack, but emphasized that no end-user data was accessed as part of the attack. #privacy #password #Bitwarden #checkmarx #hacker #breach thehackernews.com/2026/04/bitw

  2. Bitwarden CLI has been compromised as part of the newly discovered and ongoing Checkmarx supply chain campaign. Bitwarden confirmed the incident and said it stemmed from the compromise of its npm distribution mechanism following the Checkmarx supply chain attack, but emphasized that no end-user data was accessed as part of the attack. #privacy #password #Bitwarden #checkmarx #hacker #breach thehackernews.com/2026/04/bitw

  3. Bitwarden CLI has been compromised as part of the newly discovered and ongoing Checkmarx supply chain campaign. Bitwarden confirmed the incident and said it stemmed from the compromise of its npm distribution mechanism following the Checkmarx supply chain attack, but emphasized that no end-user data was accessed as part of the attack. #privacy #password #Bitwarden #checkmarx #hacker #breach thehackernews.com/2026/04/bitw

  4. Bitwarden CLI has been compromised as part of the newly discovered and ongoing Checkmarx supply chain campaign. Bitwarden confirmed the incident and said it stemmed from the compromise of its npm distribution mechanism following the Checkmarx supply chain attack, but emphasized that no end-user data was accessed as part of the attack. #privacy #password #Bitwarden #checkmarx #hacker #breach thehackernews.com/2026/04/bitw

  5. Bitwarden CLI has been compromised as part of the newly discovered and ongoing Checkmarx supply chain campaign. Bitwarden confirmed the incident and said it stemmed from the compromise of its npm distribution mechanism following the Checkmarx supply chain attack, but emphasized that no end-user data was accessed as part of the attack. #privacy #password #Bitwarden #checkmarx #hacker #breach thehackernews.com/2026/04/bitw

  6. The official Checkmarx Jenkins plugin was compromised with an infostealer, attributed to TeamPCP, marking a recurring supply-chain incident. This breach wasn't a quick hit; the actor maintained access for over a month, exploiting stolen credentials from a prior attack and even taunting Checkmarx for failing to rotate secrets. It's a stark reminder of deep issues in developer tool security and…

    tpp.blog/1yqjwps

    #cybersecurity #checkmarx #jenkins

    🤖 This post was AI-generated.

  7. Checkmarx Plugin Compromised with Infostealer in Supply-Chain Attack

    A rogue version of Checkmarx's Jenkins Application Security Testing plugin was compromised by the TeamPCP hacker group, who left a taunting message in the about section, claiming another supply-chain attack success. The group has been linked to a string of similar breaches, delivering credential-stealing malware.

    osintsights.com/checkmarx-plug

    #SupplyChainAttack #Teampcp #Jenkins #Checkmarx #Infostealer

  8. TeamPCP Breaches Checkmarx Jenkins Plugin Again

    If you're using the Checkmarx Jenkins AST plugin, make sure you're on a safe footing by using version 2.0.13-829.vc72453fa_1c16 or earlier, published on December 17, 2025, as newer versions may be vulnerable. Checkmarx has since released a patched version, 2.0.13-848.v76e89de8a_053, available on GitHub and the Jenkins Marketplace.

    osintsights.com/teampcp-breach

    #Checkmarx #JenkinsPlugin #SupplyChain #Vulnerability #EmergingThreats

  9. Checkmarx Plugin Sabotaged in Fresh TeamPCP Intrusion

    Checkmarx issued a warning on May 9, 2026, that a tampered version of its Jenkins AST plugin had been released on the Jenkins Marketplace, posing a risk to continuous-integration pipelines. The company quickly responded by urging customers to update to a trusted version, 2.0.13-829.vc72453fa_1c16, to safeguard their systems.

    osintsights.com/checkmarx-plug

    #Jenkins #Checkmarx #SupplyChain #PluginVulnerability #EmergingThreats

  10. Twórcy zabezpieczeń sami padli ofiarą hakerów. Jak atak na Trivy wywołał efekt domina

    Kiedy firmy odpowiedzialne za ochronę naszych danych same stają się celem skutecznego ataku, w całej branży zapala się czerwona lampka.

    Groźny atak na łańcuch dostaw skompromitował popularne narzędzia dla programistów, uderzając rykoszetem w gigantów cyberbezpieczeństwa – firmy Checkmarx oraz Bitwarden. To dobitny dowód na to, że przestępcy znaleźli nowy, niezwykle skuteczny wektor ataku: infekowanie samych strażników.

    Atak na łańcuch dostaw. Złośliwa aktualizacja Bitwarden CLI zagrażała deweloperom

    Efekt domina. Jak złośliwy kod zainfekował gigantów

    Wszystko zaczęło się w połowie marca od przejęcia konta na GitHubie należącego do Trivy – szeroko wykorzystywanego skanera podatności w kodzie. Hakerzy z grupy TeamPCP wykorzystali ten dostęp, by przemycić złośliwe oprogramowanie bezpośrednio do aktualizacji pobieranych przez użytkowników narzędzia. Malware błyskawicznie zaczął przeczesywać zainfekowane maszyny w poszukiwaniu tokenów dostępu, kluczy SSH i poufnych danych uwierzytelniających.

    W ten sposób przestępcy bezszelestnie włamali się do systemów firm Checkmarx oraz Bitwarden (o ataku na ten popularny menedżer haseł pisaliśmy już wcześniej). Zamiast atakować korporacje frontalnie, hakerzy weszli głównymi drzwiami, wykorzystując zaufane oprogramowanie firm trzecich.

    Podwójny koszmar Checkmarx. Od kradzieży danych po szantaż

    Dla firmy Checkmarx był to zaledwie początek trwającego ponad miesiąc kryzysu. Krótko po pierwszej infekcji, napastnicy przejęli oficjalne konto firmy na GitHubie i zaczęli rozsyłać złośliwy kod dalej – prosto do jej klientów. Choć Checkmarx poinformowało o szybkim załataniu luki, 22 kwietnia sytuacja się powtórzyła, co sugeruje, że intruzi nigdy nie utracili dostępu do infrastruktury.

    Jakby tego było mało, do gry wkroczyła niesławna grupa ransomware Lapsu$, która pod koniec kwietnia opublikowała w dark webie prywatne pliki wykradzione z serwerów Checkmarx. Wskazuje to na brutalną rynkową praktykę: grupa TeamPCP najpewniej sprzedała dostęp do przejętej sieci młodym hakerom z Lapsu$, a firma przez tygodnie nie potrafiła zidentyfikować pełnej skali włamania.

    Dlaczego hakerzy polują na narzędzia bezpieczeństwa?

    Ten incydent obnaża nową strategię cyberprzestępców. Oprogramowanie zabezpieczające jest dziś traktowane przez hakerów jednocześnie jako główny cel i idealny mechanizm dystrybucji wirusów.

    Tego typu programy mają z założenia głęboki, uprzywilejowany dostęp do najbardziej wrażliwych danych w systemach korporacyjnych. Atakując zaufane narzędzia, hakerzy jednym celnym ciosem otwierają sobie drzwi do tysięcy kolejnych ofiar w dół łańcucha dostaw. To efekt kaskadowy, który pokazuje, że w dzisiejszym świecie IT nikt nie jest w pełni bezpieczny – nawet ci, którzy ten świat chronią.

    #Bitwarden #Checkmarx #cyberbezpieczeństwo #hakerzy #Lapsu #ransomware #Trivy #wyciekDanych
  11. Twórcy zabezpieczeń sami padli ofiarą hakerów. Jak atak na Trivy wywołał efekt domina

    Kiedy firmy odpowiedzialne za ochronę naszych danych same stają się celem skutecznego ataku, w całej branży zapala się czerwona lampka.

    Groźny atak na łańcuch dostaw skompromitował popularne narzędzia dla programistów, uderzając rykoszetem w gigantów cyberbezpieczeństwa – firmy Checkmarx oraz Bitwarden. To dobitny dowód na to, że przestępcy znaleźli nowy, niezwykle skuteczny wektor ataku: infekowanie samych strażników.

    Atak na łańcuch dostaw. Złośliwa aktualizacja Bitwarden CLI zagrażała deweloperom

    Efekt domina. Jak złośliwy kod zainfekował gigantów

    Wszystko zaczęło się w połowie marca od przejęcia konta na GitHubie należącego do Trivy – szeroko wykorzystywanego skanera podatności w kodzie. Hakerzy z grupy TeamPCP wykorzystali ten dostęp, by przemycić złośliwe oprogramowanie bezpośrednio do aktualizacji pobieranych przez użytkowników narzędzia. Malware błyskawicznie zaczął przeczesywać zainfekowane maszyny w poszukiwaniu tokenów dostępu, kluczy SSH i poufnych danych uwierzytelniających.

    W ten sposób przestępcy bezszelestnie włamali się do systemów firm Checkmarx oraz Bitwarden (o ataku na ten popularny menedżer haseł pisaliśmy już wcześniej). Zamiast atakować korporacje frontalnie, hakerzy weszli głównymi drzwiami, wykorzystując zaufane oprogramowanie firm trzecich.

    Podwójny koszmar Checkmarx. Od kradzieży danych po szantaż

    Dla firmy Checkmarx był to zaledwie początek trwającego ponad miesiąc kryzysu. Krótko po pierwszej infekcji, napastnicy przejęli oficjalne konto firmy na GitHubie i zaczęli rozsyłać złośliwy kod dalej – prosto do jej klientów. Choć Checkmarx poinformowało o szybkim załataniu luki, 22 kwietnia sytuacja się powtórzyła, co sugeruje, że intruzi nigdy nie utracili dostępu do infrastruktury.

    Jakby tego było mało, do gry wkroczyła niesławna grupa ransomware Lapsu$, która pod koniec kwietnia opublikowała w dark webie prywatne pliki wykradzione z serwerów Checkmarx. Wskazuje to na brutalną rynkową praktykę: grupa TeamPCP najpewniej sprzedała dostęp do przejętej sieci młodym hakerom z Lapsu$, a firma przez tygodnie nie potrafiła zidentyfikować pełnej skali włamania.

    Dlaczego hakerzy polują na narzędzia bezpieczeństwa?

    Ten incydent obnaża nową strategię cyberprzestępców. Oprogramowanie zabezpieczające jest dziś traktowane przez hakerów jednocześnie jako główny cel i idealny mechanizm dystrybucji wirusów.

    Tego typu programy mają z założenia głęboki, uprzywilejowany dostęp do najbardziej wrażliwych danych w systemach korporacyjnych. Atakując zaufane narzędzia, hakerzy jednym celnym ciosem otwierają sobie drzwi do tysięcy kolejnych ofiar w dół łańcucha dostaw. To efekt kaskadowy, który pokazuje, że w dzisiejszym świecie IT nikt nie jest w pełni bezpieczny – nawet ci, którzy ten świat chronią.

    #Bitwarden #Checkmarx #cyberbezpieczeństwo #hakerzy #Lapsu #ransomware #Trivy #wyciekDanych
  12. Why a recent supply-chain #attack singled out #security firms #Checkmarx and #Bitwarden

    It has been a bad six weeks for security firm Checmarx. Over the past 40 days, it has been the victim of at least one supply-chain attack that delivered #malware to customers on two separate occasions. Now it has been hit by a #ransomware attack from prolific fame-seeking #hackers.
    #supplychain #privacy

    arstechnica.com/information-te

  13. Why a recent supply-chain #attack singled out #security firms #Checkmarx and #Bitwarden

    It has been a bad six weeks for security firm Checmarx. Over the past 40 days, it has been the victim of at least one supply-chain attack that delivered #malware to customers on two separate occasions. Now it has been hit by a #ransomware attack from prolific fame-seeking #hackers.
    #supplychain #privacy

    arstechnica.com/information-te

  14. Why a recent supply-chain #attack singled out #security firms #Checkmarx and #Bitwarden

    It has been a bad six weeks for security firm Checmarx. Over the past 40 days, it has been the victim of at least one supply-chain attack that delivered #malware to customers on two separate occasions. Now it has been hit by a #ransomware attack from prolific fame-seeking #hackers.
    #supplychain #privacy

    arstechnica.com/information-te

  15. Why a recent supply-chain singled out firms and

    It has been a bad six weeks for security firm Checmarx. Over the past 40 days, it has been the victim of at least one supply-chain attack that delivered to customers on two separate occasions. Now it has been hit by a attack from prolific fame-seeking .

    arstechnica.com/information-te

  16. Why a recent supply-chain #attack singled out #security firms #Checkmarx and #Bitwarden

    It has been a bad six weeks for security firm Checmarx. Over the past 40 days, it has been the victim of at least one supply-chain attack that delivered #malware to customers on two separate occasions. Now it has been hit by a #ransomware attack from prolific fame-seeking #hackers.
    #supplychain #privacy

    arstechnica.com/information-te

  17. 📰 Checkmarx Details Supply Chain Attack Stemming from Trivy Scanner Vulnerability

    🚨 Checkmarx details a supply chain attack that started with a vulnerable Trivy scanner. Attackers accessed GitHub, pushed malicious code, and leaked data on the dark web. #Checkmarx #SupplyChain #CyberAttack #GitHub

    🔗 cyber.netsecops.io

  18. From #trivy to #Checkmarx : Ongoing supply-chain attack targets security, dev tools

    Attackers are deliberately targeting the tools developers are told to trust most: security scanners, password managers, and other high-privilege software wired directly into developer environments

    theregister.com/2026/04/27/sup

  19. From #trivy to #Checkmarx : Ongoing supply-chain attack targets security, dev tools

    Attackers are deliberately targeting the tools developers are told to trust most: security scanners, password managers, and other high-privilege software wired directly into developer environments

    theregister.com/2026/04/27/sup

  20. From #trivy to #Checkmarx : Ongoing supply-chain attack targets security, dev tools

    Attackers are deliberately targeting the tools developers are told to trust most: security scanners, password managers, and other high-privilege software wired directly into developer environments

    theregister.com/2026/04/27/sup

  21. From #trivy to #Checkmarx : Ongoing supply-chain attack targets security, dev tools

    Attackers are deliberately targeting the tools developers are told to trust most: security scanners, password managers, and other high-privilege software wired directly into developer environments

    theregister.com/2026/04/27/sup

  22. From #trivy to #Checkmarx : Ongoing supply-chain attack targets security, dev tools

    Attackers are deliberately targeting the tools developers are told to trust most: security scanners, password managers, and other high-privilege software wired directly into developer environments

    theregister.com/2026/04/27/sup

  23. Checkmarx Breach Exposes GitHub Repository Data on Dark Web

    Checkmarx revealed that a security breach, linked to a March 23 supply chain attack, exposed sensitive GitHub repository data, which has now surfaced on the dark web. The incident has been contained, with no customer data compromised, as the affected repository was separate from Checkmarx's customer production environment.

    osintsights.com/checkmarx-brea

    #SupplyChain #Github #Trivy #Checkmarx #DarkWeb

  24. Bitwarden CLI was compromised via the Checkmarx supply‑chain campaign—attackers injected malicious code into @bitwarden/cli v2026.4.0 through a poisoned CI/CD GitHub Action. Users should avoid v2026.4.0, rotate keys, and audit CI/CD. Details: cyberinsider.com/bitwarden-cli 🚨🔒⚠️ #SupplyChainAttack #InfoSec #Bitwarden #Checkmarx

  25. Bitwarden CLI was compromised via the Checkmarx supply‑chain campaign—attackers injected malicious code into @bitwarden/cli v2026.4.0 through a poisoned CI/CD GitHub Action. Users should avoid v2026.4.0, rotate keys, and audit CI/CD. Details: cyberinsider.com/bitwarden-cli 🚨🔒⚠️ #SupplyChainAttack #InfoSec #Bitwarden #Checkmarx

  26. Bitwarden CLI was compromised via the Checkmarx supply‑chain campaign—attackers injected malicious code into @bitwarden/cli v2026.4.0 through a poisoned CI/CD GitHub Action. Users should avoid v2026.4.0, rotate keys, and audit CI/CD. Details: cyberinsider.com/bitwarden-cli 🚨🔒⚠️ #SupplyChainAttack #InfoSec #Bitwarden #Checkmarx

  27. Bitwarden CLI was compromised via the Checkmarx supply‑chain campaign—attackers injected malicious code into @bitwarden/cli v2026.4.0 through a poisoned CI/CD GitHub Action. Users should avoid v2026.4.0, rotate keys, and audit CI/CD. Details: cyberinsider.com/bitwarden-cli 🚨🔒⚠️

  28. Bitwarden CLI was compromised via the Checkmarx supply‑chain campaign—attackers injected malicious code into @bitwarden/cli v2026.4.0 through a poisoned CI/CD GitHub Action. Users should avoid v2026.4.0, rotate keys, and audit CI/CD. Details: cyberinsider.com/bitwarden-cli 🚨🔒⚠️ #SupplyChainAttack #InfoSec #Bitwarden #Checkmarx