Newsgather

supply_chain_attack

مستقر12 خبر6 مصادرآخر تحديث: 22.05.2026

أحدث الأخبار

Checkmarx Hit by Supply Chain Attack, Then Ransomware in Cascading Security Breaches
يتطور
تقنية·29.04.2026ملخص الذكاء الاصطناعي

Checkmarx Hit by Supply Chain Attack, Then Ransomware in Cascading Security Breaches

Checkmarx, a security firm, has suffered a devastating series of breaches over 40 days. It was first compromised through a supply-chain attack on the Trivy vulnerability scanner on March 19, with attackers pushing malware that stole credentials. Checkmarx's own GitHub account was then breached on March 23, pushing malware to its users. Despite remediation, a new malware wave appeared April 22. The Lapsu$ ransomware group subsequently dumped stolen data on the dark web on March 30, originating from Checkmarx's GitHub repositories. Another security firm, Bitwarden, was also affected in the same Trivy supply-chain attack.

A
Ars Technica
Open Source element-data Package Compromised in Supply Chain Attack
مُلِح
تقنية·27.04.2026ملخص الذكاء الاصطناعي

Open Source element-data Package Compromised in Supply Chain Attack

A supply chain attack compromised element-data, an open source CLI for monitoring ML systems. Attackers exploited a vulnerability in a GitHub action to steal developer account tokens and signing keys, then published malicious version 0.23.3 that scraped credentials from infected systems. The package was removed within 12 hours, but users who installed it should assume credentials were exposed and rotate all sensitive access keys immediately.

A
Ars Technica