Close Menu
    Facebook LinkedIn YouTube WhatsApp X (Twitter) Pinterest
    Trending
    • This region in space poses the greatest danger in our Solar System
    • Practical info and special tips for the EU-Startups Summit 2026 in Malta – look inside!
    • Your Phone Notifications Reveal More Than You Realize. Here’s How to Lock Them Down
    • Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden
    • iPad Pro M5 Review: Closer Than Ever to the Future Mac
    • How AI Policy in South Africa Is Ruining Itself
    • Dual iris laser projector offers theater blacks
    • The Startup World Cup is your chance to pitch in Silicon Valley and win $1.4 million
    Facebook LinkedIn WhatsApp
    Times FeaturedTimes Featured
    Wednesday, April 29
    • Home
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    • More
      • AI
      • Robotics
      • Industries
      • Global
    Times FeaturedTimes Featured
    Home»News»Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden
    News

    Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden

    Editor Times FeaturedBy Editor Times FeaturedApril 29, 2026No Comments2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email WhatsApp Copy Link

    “Present proof signifies that this knowledge originated from Checkmarx’s GitHub repositories, and that entry to these repositories was facilitated by way of the preliminary provide chain assault of March 23, 2023,” Checkmarx stated Monday. The corporate didn’t say what varieties of information had been leaked.

    Checkmarx isn’t the one safety firm to endure the aftereffects of the Trivy breach. Socket said that one other safety agency, Bitwarden, was additionally hit in the identical supply-chain assault. Socket tied the Bitwarden breach to the Trivy marketing campaign as a result of the payload used the identical C2 endpoint and core infrastructure because the Checkmarx malware.

    The Trivy assault was carried out by a bunch calling itself TeamPCP. The group is among the many most profitable access-broker operations, a category of hackers that smashes and grabs credentials from victims after which sells them to different hackers. The important thing to its ascendency is its concentrating on of instruments that have already got privileged entry.

    Within the case of Checkmarx, it seems TeamPCP bought entry credentials to Lapsu$, a ransomware group made up mostly of teenagers generally known as a lot for its talent in breaching giant firms as it’s for its taunts and braggadocio as soon as it succeeds.

    The incidents display the cascading results a single breach can have. With each Checkmarx and Bitwarden affected, it’s potential that there will probably be new assaults on their prospects or companions and that much more downstream compromises may consequence from these. Socket CEO Feross Aboukhadijeh stated in an electronic mail that safety organizations are specific targets due to their merchandise’ shut proximity to delicate knowledge and their vast distribution throughout the Web.

    “You will note this identical thread all through these compromises,” Aboukhadijeh stated. “Attackers are treating safety instruments as each a goal and a supply mechanism. They’re attacking the merchandise which might be supposed to guard the availability chain, then utilizing those self same merchandise to steal credentials and transfer to the subsequent sufferer.”



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Editor Times Featured
    • Website

    Related Posts

    The European Commission issues preliminary DSA findings against Meta, saying Instagram and Facebook fail to prevent under-13 users from accessing the services (Gian Volpicelli/Bloomberg)

    April 29, 2026

    Alberta online gambling expansion sparks concern among First Nations casino operators

    April 29, 2026

    Better Markets urges courts to let states regulate prediction markets, not CFTC

    April 29, 2026

    Q&A with Sam Altman and AWS CEO Matt Garman about OpenAI’s new partnership with AWS, Bedrock Managed Agents, Trainium chips, and more (Ben Thompson/Stratechery)

    April 28, 2026

    Snapchat launches AI Sponsored Snaps, a conversational ad format in the Chat tab that lets users talk to brand-specific AI agents for product recommendations (Aisha Malik/TechCrunch)

    April 28, 2026

    AI researchers launch talkie, a 13B vintage language model trained on historical text with a 1930 cutoff, to see if it can replicate scientific breakthroughs (talkie)

    April 28, 2026
    Leave A Reply Cancel Reply

    Editors Picks

    This region in space poses the greatest danger in our Solar System

    April 29, 2026

    Practical info and special tips for the EU-Startups Summit 2026 in Malta – look inside!

    April 29, 2026

    Your Phone Notifications Reveal More Than You Realize. Here’s How to Lock Them Down

    April 29, 2026

    Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden

    April 29, 2026
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    About Us
    About Us

    Welcome to Times Featured, an AI-driven entrepreneurship growth engine that is transforming the future of work, bridging the digital divide and encouraging younger community inclusion in the 4th Industrial Revolution, and nurturing new market leaders.

    Empowering the growth of profiles, leaders, entrepreneurs businesses, and startups on international landscape.

    Asia-Middle East-Europe-North America-Australia-Africa

    Facebook LinkedIn WhatsApp
    Featured Picks

    Best Vacuum Deals for Amazon’s Spring Sale: Dyson, Shark, Bissell (2026)

    March 26, 2026

    Humanoid Robots Headed to War? I Went Hands-On With the Phantom MK1

    October 12, 2025

    Winston AI Plagiarism Checker: My Unfiltered Thoughts

    September 15, 2025
    Categories
    • Founders
    • Startups
    • Technology
    • Profiles
    • Entrepreneurs
    • Leaders
    • Students
    • VC Funds
    Copyright © 2024 Timesfeatured.com IP Limited. All Rights.
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • About us
    • Contact us

    Type above and press Enter to search. Press Esc to cancel.