#checkmarx — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #checkmarx, aggregated by home.social.
-
Bitwarden CLI has been compromised as part of the newly discovered and ongoing Checkmarx supply chain campaign. Bitwarden confirmed the incident and said it stemmed from the compromise of its npm distribution mechanism following the Checkmarx supply chain attack, but emphasized that no end-user data was accessed as part of the attack. #privacy #password #Bitwarden #checkmarx #hacker #breach https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html
-
Bitwarden CLI has been compromised as part of the newly discovered and ongoing Checkmarx supply chain campaign. Bitwarden confirmed the incident and said it stemmed from the compromise of its npm distribution mechanism following the Checkmarx supply chain attack, but emphasized that no end-user data was accessed as part of the attack. #privacy #password #Bitwarden #checkmarx #hacker #breach https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html
-
Bitwarden CLI has been compromised as part of the newly discovered and ongoing Checkmarx supply chain campaign. Bitwarden confirmed the incident and said it stemmed from the compromise of its npm distribution mechanism following the Checkmarx supply chain attack, but emphasized that no end-user data was accessed as part of the attack. #privacy #password #Bitwarden #checkmarx #hacker #breach https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html
-
Bitwarden CLI has been compromised as part of the newly discovered and ongoing Checkmarx supply chain campaign. Bitwarden confirmed the incident and said it stemmed from the compromise of its npm distribution mechanism following the Checkmarx supply chain attack, but emphasized that no end-user data was accessed as part of the attack. #privacy #password #Bitwarden #checkmarx #hacker #breach https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html
-
Bitwarden CLI has been compromised as part of the newly discovered and ongoing Checkmarx supply chain campaign. Bitwarden confirmed the incident and said it stemmed from the compromise of its npm distribution mechanism following the Checkmarx supply chain attack, but emphasized that no end-user data was accessed as part of the attack. #privacy #password #Bitwarden #checkmarx #hacker #breach https://thehackernews.com/2026/04/bitwarden-cli-compromised-in-ongoing.html
-
📢 Le plugin Jenkins de Checkmarx compromis par TeamPCP dans une série d'attaques supply-chain
📝 ## 🔍 ContexteSource...
📖 cyberveille : https://cyberveille.ch/posts/2026-05-15-le-plugin-jenkins-de-checkmarx-compromis-par-teampcp-dans-une-serie-d-attaques-supply-chain/
🌐 source : https://www.bleepingcomputer.com/news/security/official-checkmarx-jenkins-package-compromised-with-infostealer/
#Checkmarx #Checkmarx_Jenkins_AST_plugin__version_malveillante_2026_5_09_ #Cyberveille -
📢 Incident supply chain Checkmarx : artefacts compromis, exfiltration de données et publication par LAPSUS$
📝 ## 🔍 ContexteCet article est une mise à jo...
📖 cyberveille : https://cyberveille.ch/posts/2026-05-13-incident-supply-chain-checkmarx-artefacts-compromis-exfiltration-de-donnees-et-publication-par-lapsus/
🌐 source : https://checkmarx.com/blog/ongoing-security-updates/?is=e4f6b16c6de31130985364bb824bcb39ef6b2c4e902e4e553f0ec11bdbefc118
#Checkmarx #Docker #Cyberveille -
#Checkmarx is breached again via its Jenkins plugin GitHub repo compromised in a software suply chain hack:
#SoftwareSupplyChainSecurity
👇 -
#Checkmarx is breached again via its Jenkins plugin GitHub repo compromised in a software suply chain hack:
#SoftwareSupplyChainSecurity
👇 -
#Checkmarx is breached again via its Jenkins plugin GitHub repo compromised in a software suply chain hack:
#SoftwareSupplyChainSecurity
👇 -
#Checkmarx is breached again via its Jenkins plugin GitHub repo compromised in a software suply chain hack:
#SoftwareSupplyChainSecurity
👇 -
#Checkmarx is breached again via its Jenkins plugin GitHub repo compromised in a software suply chain hack:
#SoftwareSupplyChainSecurity
👇 -
The official Checkmarx Jenkins plugin was compromised with an infostealer, attributed to TeamPCP, marking a recurring supply-chain incident. This breach wasn't a quick hit; the actor maintained access for over a month, exploiting stolen credentials from a prior attack and even taunting Checkmarx for failing to rotate secrets. It's a stark reminder of deep issues in developer tool security and…
#cybersecurity #checkmarx #jenkins
🤖 This post was AI-generated.
-
Checkmarx Plugin Compromised with Infostealer in Supply-Chain Attack
A rogue version of Checkmarx's Jenkins Application Security Testing plugin was compromised by the TeamPCP hacker group, who left a taunting message in the about section, claiming another supply-chain attack success. The group has been linked to a string of similar breaches, delivering credential-stealing malware.
#SupplyChainAttack #Teampcp #Jenkins #Checkmarx #Infostealer
-
TeamPCP Breaches Checkmarx Jenkins Plugin Again
If you're using the Checkmarx Jenkins AST plugin, make sure you're on a safe footing by using version 2.0.13-829.vc72453fa_1c16 or earlier, published on December 17, 2025, as newer versions may be vulnerable. Checkmarx has since released a patched version, 2.0.13-848.v76e89de8a_053, available on GitHub and the Jenkins Marketplace.
#Checkmarx #JenkinsPlugin #SupplyChain #Vulnerability #EmergingThreats
-
Checkmarx Plugin Sabotaged in Fresh TeamPCP Intrusion
Checkmarx issued a warning on May 9, 2026, that a tampered version of its Jenkins AST plugin had been released on the Jenkins Marketplace, posing a risk to continuous-integration pipelines. The company quickly responded by urging customers to update to a trusted version, 2.0.13-829.vc72453fa_1c16, to safeguard their systems.
#Jenkins #Checkmarx #SupplyChain #PluginVulnerability #EmergingThreats
-
Twórcy zabezpieczeń sami padli ofiarą hakerów. Jak atak na Trivy wywołał efekt domina
Kiedy firmy odpowiedzialne za ochronę naszych danych same stają się celem skutecznego ataku, w całej branży zapala się czerwona lampka.
Groźny atak na łańcuch dostaw skompromitował popularne narzędzia dla programistów, uderzając rykoszetem w gigantów cyberbezpieczeństwa – firmy Checkmarx oraz Bitwarden. To dobitny dowód na to, że przestępcy znaleźli nowy, niezwykle skuteczny wektor ataku: infekowanie samych strażników.
Atak na łańcuch dostaw. Złośliwa aktualizacja Bitwarden CLI zagrażała deweloperom
Efekt domina. Jak złośliwy kod zainfekował gigantów
Wszystko zaczęło się w połowie marca od przejęcia konta na GitHubie należącego do Trivy – szeroko wykorzystywanego skanera podatności w kodzie. Hakerzy z grupy TeamPCP wykorzystali ten dostęp, by przemycić złośliwe oprogramowanie bezpośrednio do aktualizacji pobieranych przez użytkowników narzędzia. Malware błyskawicznie zaczął przeczesywać zainfekowane maszyny w poszukiwaniu tokenów dostępu, kluczy SSH i poufnych danych uwierzytelniających.
W ten sposób przestępcy bezszelestnie włamali się do systemów firm Checkmarx oraz Bitwarden (o ataku na ten popularny menedżer haseł pisaliśmy już wcześniej). Zamiast atakować korporacje frontalnie, hakerzy weszli głównymi drzwiami, wykorzystując zaufane oprogramowanie firm trzecich.
Podwójny koszmar Checkmarx. Od kradzieży danych po szantaż
Dla firmy Checkmarx był to zaledwie początek trwającego ponad miesiąc kryzysu. Krótko po pierwszej infekcji, napastnicy przejęli oficjalne konto firmy na GitHubie i zaczęli rozsyłać złośliwy kod dalej – prosto do jej klientów. Choć Checkmarx poinformowało o szybkim załataniu luki, 22 kwietnia sytuacja się powtórzyła, co sugeruje, że intruzi nigdy nie utracili dostępu do infrastruktury.
Jakby tego było mało, do gry wkroczyła niesławna grupa ransomware Lapsu$, która pod koniec kwietnia opublikowała w dark webie prywatne pliki wykradzione z serwerów Checkmarx. Wskazuje to na brutalną rynkową praktykę: grupa TeamPCP najpewniej sprzedała dostęp do przejętej sieci młodym hakerom z Lapsu$, a firma przez tygodnie nie potrafiła zidentyfikować pełnej skali włamania.
Dlaczego hakerzy polują na narzędzia bezpieczeństwa?
Ten incydent obnaża nową strategię cyberprzestępców. Oprogramowanie zabezpieczające jest dziś traktowane przez hakerów jednocześnie jako główny cel i idealny mechanizm dystrybucji wirusów.
Tego typu programy mają z założenia głęboki, uprzywilejowany dostęp do najbardziej wrażliwych danych w systemach korporacyjnych. Atakując zaufane narzędzia, hakerzy jednym celnym ciosem otwierają sobie drzwi do tysięcy kolejnych ofiar w dół łańcucha dostaw. To efekt kaskadowy, który pokazuje, że w dzisiejszym świecie IT nikt nie jest w pełni bezpieczny – nawet ci, którzy ten świat chronią.
#Bitwarden #Checkmarx #cyberbezpieczeństwo #hakerzy #Lapsu #ransomware #Trivy #wyciekDanych -
Twórcy zabezpieczeń sami padli ofiarą hakerów. Jak atak na Trivy wywołał efekt domina
Kiedy firmy odpowiedzialne za ochronę naszych danych same stają się celem skutecznego ataku, w całej branży zapala się czerwona lampka.
Groźny atak na łańcuch dostaw skompromitował popularne narzędzia dla programistów, uderzając rykoszetem w gigantów cyberbezpieczeństwa – firmy Checkmarx oraz Bitwarden. To dobitny dowód na to, że przestępcy znaleźli nowy, niezwykle skuteczny wektor ataku: infekowanie samych strażników.
Atak na łańcuch dostaw. Złośliwa aktualizacja Bitwarden CLI zagrażała deweloperom
Efekt domina. Jak złośliwy kod zainfekował gigantów
Wszystko zaczęło się w połowie marca od przejęcia konta na GitHubie należącego do Trivy – szeroko wykorzystywanego skanera podatności w kodzie. Hakerzy z grupy TeamPCP wykorzystali ten dostęp, by przemycić złośliwe oprogramowanie bezpośrednio do aktualizacji pobieranych przez użytkowników narzędzia. Malware błyskawicznie zaczął przeczesywać zainfekowane maszyny w poszukiwaniu tokenów dostępu, kluczy SSH i poufnych danych uwierzytelniających.
W ten sposób przestępcy bezszelestnie włamali się do systemów firm Checkmarx oraz Bitwarden (o ataku na ten popularny menedżer haseł pisaliśmy już wcześniej). Zamiast atakować korporacje frontalnie, hakerzy weszli głównymi drzwiami, wykorzystując zaufane oprogramowanie firm trzecich.
Podwójny koszmar Checkmarx. Od kradzieży danych po szantaż
Dla firmy Checkmarx był to zaledwie początek trwającego ponad miesiąc kryzysu. Krótko po pierwszej infekcji, napastnicy przejęli oficjalne konto firmy na GitHubie i zaczęli rozsyłać złośliwy kod dalej – prosto do jej klientów. Choć Checkmarx poinformowało o szybkim załataniu luki, 22 kwietnia sytuacja się powtórzyła, co sugeruje, że intruzi nigdy nie utracili dostępu do infrastruktury.
Jakby tego było mało, do gry wkroczyła niesławna grupa ransomware Lapsu$, która pod koniec kwietnia opublikowała w dark webie prywatne pliki wykradzione z serwerów Checkmarx. Wskazuje to na brutalną rynkową praktykę: grupa TeamPCP najpewniej sprzedała dostęp do przejętej sieci młodym hakerom z Lapsu$, a firma przez tygodnie nie potrafiła zidentyfikować pełnej skali włamania.
Dlaczego hakerzy polują na narzędzia bezpieczeństwa?
Ten incydent obnaża nową strategię cyberprzestępców. Oprogramowanie zabezpieczające jest dziś traktowane przez hakerów jednocześnie jako główny cel i idealny mechanizm dystrybucji wirusów.
Tego typu programy mają z założenia głęboki, uprzywilejowany dostęp do najbardziej wrażliwych danych w systemach korporacyjnych. Atakując zaufane narzędzia, hakerzy jednym celnym ciosem otwierają sobie drzwi do tysięcy kolejnych ofiar w dół łańcucha dostaw. To efekt kaskadowy, który pokazuje, że w dzisiejszym świecie IT nikt nie jest w pełni bezpieczny – nawet ci, którzy ten świat chronią.
#Bitwarden #Checkmarx #cyberbezpieczeństwo #hakerzy #Lapsu #ransomware #Trivy #wyciekDanych -
Why a recent supply-chain attack singled out security firms #Checkmarx and #Bitwarden
-
Why a recent supply-chain attack singled out security firms #Checkmarx and #Bitwarden
-
Why a recent supply-chain attack singled out security firms #Checkmarx and #Bitwarden
-
Why a recent supply-chain attack singled out security firms #Checkmarx and #Bitwarden
-
Why a recent supply-chain attack singled out security firms #Checkmarx and #Bitwarden
-
#Checkmarx confirms #LAPSUS$ hackers leaked its stolen #GitHub data
-
#Checkmarx confirms #LAPSUS$ hackers leaked its stolen #GitHub data
-
#Checkmarx confirms #LAPSUS$ hackers leaked its stolen #GitHub data
-
#Checkmarx confirms #LAPSUS$ hackers leaked its stolen #GitHub data
-
#Checkmarx confirms #LAPSUS$ hackers leaked its stolen #GitHub data
-
Why a recent supply-chain #attack singled out #security firms #Checkmarx and #Bitwarden
It has been a bad six weeks for security firm Checmarx. Over the past 40 days, it has been the victim of at least one supply-chain attack that delivered #malware to customers on two separate occasions. Now it has been hit by a #ransomware attack from prolific fame-seeking #hackers.
#supplychain #privacy -
Why a recent supply-chain #attack singled out #security firms #Checkmarx and #Bitwarden
It has been a bad six weeks for security firm Checmarx. Over the past 40 days, it has been the victim of at least one supply-chain attack that delivered #malware to customers on two separate occasions. Now it has been hit by a #ransomware attack from prolific fame-seeking #hackers.
#supplychain #privacy -
Why a recent supply-chain #attack singled out #security firms #Checkmarx and #Bitwarden
It has been a bad six weeks for security firm Checmarx. Over the past 40 days, it has been the victim of at least one supply-chain attack that delivered #malware to customers on two separate occasions. Now it has been hit by a #ransomware attack from prolific fame-seeking #hackers.
#supplychain #privacy -
Why a recent supply-chain #attack singled out #security firms #Checkmarx and #Bitwarden
It has been a bad six weeks for security firm Checmarx. Over the past 40 days, it has been the victim of at least one supply-chain attack that delivered #malware to customers on two separate occasions. Now it has been hit by a #ransomware attack from prolific fame-seeking #hackers.
#supplychain #privacy -
Why a recent supply-chain #attack singled out #security firms #Checkmarx and #Bitwarden
It has been a bad six weeks for security firm Checmarx. Over the past 40 days, it has been the victim of at least one supply-chain attack that delivered #malware to customers on two separate occasions. Now it has been hit by a #ransomware attack from prolific fame-seeking #hackers.
#supplychain #privacy -
📰 Checkmarx Details Supply Chain Attack Stemming from Trivy Scanner Vulnerability
🚨 Checkmarx details a supply chain attack that started with a vulnerable Trivy scanner. Attackers accessed GitHub, pushed malicious code, and leaked data on the dark web. #Checkmarx #SupplyChain #CyberAttack #GitHub
-
From #trivy to #Checkmarx : Ongoing supply-chain attack targets security, dev tools
Attackers are deliberately targeting the tools developers are told to trust most: security scanners, password managers, and other high-privilege software wired directly into developer environments
https://www.theregister.com/2026/04/27/supply_chain_campaign_targets_security/
-
From #trivy to #Checkmarx : Ongoing supply-chain attack targets security, dev tools
Attackers are deliberately targeting the tools developers are told to trust most: security scanners, password managers, and other high-privilege software wired directly into developer environments
https://www.theregister.com/2026/04/27/supply_chain_campaign_targets_security/
-
From #trivy to #Checkmarx : Ongoing supply-chain attack targets security, dev tools
Attackers are deliberately targeting the tools developers are told to trust most: security scanners, password managers, and other high-privilege software wired directly into developer environments
https://www.theregister.com/2026/04/27/supply_chain_campaign_targets_security/
-
From #trivy to #Checkmarx : Ongoing supply-chain attack targets security, dev tools
Attackers are deliberately targeting the tools developers are told to trust most: security scanners, password managers, and other high-privilege software wired directly into developer environments
https://www.theregister.com/2026/04/27/supply_chain_campaign_targets_security/
-
From #trivy to #Checkmarx : Ongoing supply-chain attack targets security, dev tools
Attackers are deliberately targeting the tools developers are told to trust most: security scanners, password managers, and other high-privilege software wired directly into developer environments
https://www.theregister.com/2026/04/27/supply_chain_campaign_targets_security/
-
Checkmarx Breach Exposes GitHub Repository Data on Dark Web
Checkmarx revealed that a security breach, linked to a March 23 supply chain attack, exposed sensitive GitHub repository data, which has now surfaced on the dark web. The incident has been contained, with no customer data compromised, as the affected repository was separate from Checkmarx's customer production environment.
-
Bitwarden CLI was compromised via the Checkmarx supply‑chain campaign—attackers injected malicious code into @bitwarden/cli v2026.4.0 through a poisoned CI/CD GitHub Action. Users should avoid v2026.4.0, rotate keys, and audit CI/CD. Details: https://cyberinsider.com/bitwarden-cli-backdoored-in-checkmarx-supply-chain-attack/ 🚨🔒⚠️ #SupplyChainAttack #InfoSec #Bitwarden #Checkmarx
-
Bitwarden CLI was compromised via the Checkmarx supply‑chain campaign—attackers injected malicious code into @bitwarden/cli v2026.4.0 through a poisoned CI/CD GitHub Action. Users should avoid v2026.4.0, rotate keys, and audit CI/CD. Details: https://cyberinsider.com/bitwarden-cli-backdoored-in-checkmarx-supply-chain-attack/ 🚨🔒⚠️ #SupplyChainAttack #InfoSec #Bitwarden #Checkmarx
-
Bitwarden CLI was compromised via the Checkmarx supply‑chain campaign—attackers injected malicious code into @bitwarden/cli v2026.4.0 through a poisoned CI/CD GitHub Action. Users should avoid v2026.4.0, rotate keys, and audit CI/CD. Details: https://cyberinsider.com/bitwarden-cli-backdoored-in-checkmarx-supply-chain-attack/ 🚨🔒⚠️ #SupplyChainAttack #InfoSec #Bitwarden #Checkmarx
-
Bitwarden CLI was compromised via the Checkmarx supply‑chain campaign—attackers injected malicious code into @bitwarden/cli v2026.4.0 through a poisoned CI/CD GitHub Action. Users should avoid v2026.4.0, rotate keys, and audit CI/CD. Details: https://cyberinsider.com/bitwarden-cli-backdoored-in-checkmarx-supply-chain-attack/ 🚨🔒⚠️ #SupplyChainAttack #InfoSec #Bitwarden #Checkmarx
-
Bitwarden CLI was compromised via the Checkmarx supply‑chain campaign—attackers injected malicious code into @bitwarden/cli v2026.4.0 through a poisoned CI/CD GitHub Action. Users should avoid v2026.4.0, rotate keys, and audit CI/CD. Details: https://cyberinsider.com/bitwarden-cli-backdoored-in-checkmarx-supply-chain-attack/ 🚨🔒⚠️ #SupplyChainAttack #InfoSec #Bitwarden #Checkmarx