Close Menu
AI News TodayAI News Today

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Review: Resident Evil might just be the best gaming adaptation yet

    Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data

    OpenAI wants to consult elite mathematicians about how to not fumble again

    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook X (Twitter) Instagram Pinterest Vimeo
    AI News TodayAI News Today
    • Home
    • AI News
    • AI Reviews
    • AI Tools
    • AI Tutorials
    • Chatbots
    • Free AI Tools
    • Artificial Intelligence
    AI News TodayAI News Today
    Home»Chatbots»Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden
    Chatbots

    Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden

    By Updated:No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    A cartoon man runs across a white field of ones and zeroes.
    Share
    Facebook Twitter LinkedIn Pinterest Email

    “Current evidence indicates that this data originated from Checkmarx’s GitHub repositories, and that access to those repositories was facilitated through the initial supply chain attack of March 23, 2023,” Checkmarx said Monday. The company didn’t say what kinds of data were leaked.

    Checkmarx isn’t the only security company to suffer the aftereffects of the Trivy breach. Socket said that another security firm, Bitwarden, was also hit in the same supply-chain attack. Socket tied the Bitwarden breach to the Trivy campaign because the payload used the same C2 endpoint and core infrastructure as the Checkmarx malware.

    The Trivy attack was carried out by a group calling itself TeamPCP. The group is among the most successful access-broker operations, a class of hackers that smashes and grabs credentials from victims and then sells them to other hackers. The key to its ascendency is its targeting of tools that already have privileged access.

    In the case of Checkmarx, it appears TeamPCP sold access credentials to Lapsu$, a ransomware group made up mostly of teenagers known as much for its skill in breaching large companies as its taunts and braggadocio once it succeeds.

    The incidents demonstrate the cascading effects a single breach can have. With both Checkmarx and Bitwarden affected, it’s possible that there will be new attacks on their customers or partners, and that even more downstream compromises could result from those. Socket CEO Feross Aboukhadijeh said in an email that security organizations are particular targets because of their products’ close proximity to sensitive data and their wide distribution across the Internet.

    “You will see this same thread throughout these compromises,” Aboukhadijeh said. “Attackers are treating security tools as both a target and a delivery mechanism. They are attacking the products that are supposed to protect the supply chain, then using those same products to steal credentials and move to the next victim.”

    attack Bitwarden Checkmarx firms security singled SupplyChain
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous Article‘The Boys’ Just Sorta Dropped a ‘Supernatural’ Reunion Episode, and It Was Super Messy
    Next Article Check your gravity with NASA’s Artemis II zero-g indicator
    • Website

    Related Posts

    Chatbots

    Review: Resident Evil might just be the best gaming adaptation yet

    Chatbots

    OpenAI wants to consult elite mathematicians about how to not fumble again

    Chatbots

    Meta admits Muse’s likeness to OpenClaw isn’t a coincidence

    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    Review: Resident Evil might just be the best gaming adaptation yet

    0 Views

    Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data

    0 Views

    OpenAI wants to consult elite mathematicians about how to not fumble again

    0 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    AI Tutorials

    Quantization from the ground up

    AI Tools

    David Sacks is done as AI czar — here’s what he’s doing instead

    AI Reviews

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    Review: Resident Evil might just be the best gaming adaptation yet

    0 Views

    Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data

    0 Views

    OpenAI wants to consult elite mathematicians about how to not fumble again

    0 Views
    Our Picks

    Quantization from the ground up

    David Sacks is done as AI czar — here’s what he’s doing instead

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Terms & Conditions
    • Privacy Policy
    • Disclaimer

    © 2026 ainewstoday.co. All rights reserved. Designed by DD.

    Type above and press Enter to search. Press Esc to cancel.