Checkmarx Hit by Supply Chain Attack, Then Ransomware in Cascading Security Breaches
Checkmarx, a security firm, has suffered a devastating series of breaches over 40 days. It was first compromised through a supply-chain attack on the Trivy vulnerability scanner on March 19, with attackers pushing malware that stole credentials. Checkmarx's own GitHub account was then breached on March 23, pushing malware to its users. Despite remediation, a new malware wave appeared April 22. The Lapsu$ ransomware group subsequently dumped stolen data on the dark web on March 30, originating from Checkmarx's GitHub repositories. Another security firm, Bitwarden, was also affected in the same Trivy supply-chain attack.