Ongoing supply-chain attack 'explicitly targeting' security, dev tools
ID: a45cde4c-c54a-5582-88cf-1fa504911a70
STIX ID: report--a45cde4c-c54a-5582-88cf-1fa504911a70
Feed Name: The Register (Security)
### Executive summary Checkmarx has been impacted by a supply-chain attack linked to TeamPCP and Lapsus$, where credential-stealing malware introduced via compromised tools (Trivy, KICS, etc.) and poisoned artifacts resulted in stolen source code, API keys, database credentials, and employee data; the intrusion expanded to affect developer tooling including Bitwarden's CLI and GitHub repositories, creating a large blast radius and enabling follow-on extortion and potential ransomware campaigns while investigations continue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
