Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden
ID: b3cc26fa-5fbb-5480-96b9-80246f67252a
STIX ID: report--b3cc26fa-5fbb-5480-96b9-80246f67252a
Feed Name: Security - Ars Technica
Threat Score
A supply-chain attack attributed to the Trivy campaign and the access-broker TeamPCP compromised Checkmarx and Bitwarden repositories, with access reportedly sold to the Lapsu$ ransomware group; a malicious npm package and shared C2 infrastructure linked the incidents, raising the risk of downstream credential theft and further compromises.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
