Close Menu
AI News TodayAI News Today

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    System Design Series: Apache Flink from 10,000 Feet, and Building a Flink-powered Recommendation Engine

    Jack Dorsey-backed Vine reboot Divine launches to the public

    Check your gravity with NASA’s Artemis II zero-g indicator

    Facebook X (Twitter) Instagram
    • About Us
    • Contact Us
    Facebook X (Twitter) Instagram Pinterest Vimeo
    AI News TodayAI News Today
    • Home
    • Shop
    • AI News
    • AI Reviews
    • AI Tools
    • AI Tutorials
    • Chatbots
    • Free AI Tools
    AI News TodayAI News Today
    Home»Chatbots»Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden
    Chatbots

    Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden

    By No Comments2 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    A cartoon man runs across a white field of ones and zeroes.
    Share
    Facebook Twitter LinkedIn Pinterest Email

    “Current evidence indicates that this data originated from Checkmarx’s GitHub repositories, and that access to those repositories was facilitated through the initial supply chain attack of March 23, 2023,” Checkmarx said Monday. The company didn’t say what kinds of data were leaked.

    Checkmarx isn’t the only security company to suffer the aftereffects of the Trivy breach. Socket said that another security firm, Bitwarden, was also hit in the same supply-chain attack. Socket tied the Bitwarden breach to the Trivy campaign because the payload used the same C2 endpoint and core infrastructure as the Checkmarx malware.

    The Trivy attack was carried out by a group calling itself TeamPCP. The group is among the most successful access-broker operations, a class of hackers that smashes and grabs credentials from victims and then sells them to other hackers. The key to its ascendency is its targeting of tools that already have privileged access.

    In the case of Checkmarx, it appears TeamPCP sold access credentials to Lapsu$, a ransomware group made up mostly of teenagers known as much for its skill in breaching large companies as its taunts and braggadocio once it succeeds.

    The incidents demonstrate the cascading effects a single breach can have. With both Checkmarx and Bitwarden affected, it’s possible that there will be new attacks on their customers or partners, and that even more downstream compromises could result from those. Socket CEO Feross Aboukhadijeh said in an email that security organizations are particular targets because of their products’ close proximity to sensitive data and their wide distribution across the Internet.

    “You will see this same thread throughout these compromises,” Aboukhadijeh said. “Attackers are treating security tools as both a target and a delivery mechanism. They are attacking the products that are supposed to protect the supply chain, then using those same products to steal credentials and move to the next victim.”

    attack Bitwarden Checkmarx firms security singled SupplyChain
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous Article‘The Boys’ Just Sorta Dropped a ‘Supernatural’ Reunion Episode, and It Was Super Messy
    Next Article Check your gravity with NASA’s Artemis II zero-g indicator
    • Website

    Related Posts

    Chatbots

    Jack Dorsey-backed Vine reboot Divine launches to the public

    Chatbots

    When Robots Have Their ChatGPT Moment, Remember These Pincers

    Chatbots

    Elon Musk takes the stand in high-profile trial against OpenAI

    Add A Comment
    Leave A Reply Cancel Reply

    Top Posts

    System Design Series: Apache Flink from 10,000 Feet, and Building a Flink-powered Recommendation Engine

    0 Views

    Jack Dorsey-backed Vine reboot Divine launches to the public

    0 Views

    Check your gravity with NASA’s Artemis II zero-g indicator

    0 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    AI Tutorials

    Quantization from the ground up

    AI Tools

    David Sacks is done as AI czar — here’s what he’s doing instead

    AI Reviews

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Most Popular

    System Design Series: Apache Flink from 10,000 Feet, and Building a Flink-powered Recommendation Engine

    0 Views

    Jack Dorsey-backed Vine reboot Divine launches to the public

    0 Views

    Check your gravity with NASA’s Artemis II zero-g indicator

    0 Views
    Our Picks

    Quantization from the ground up

    David Sacks is done as AI czar — here’s what he’s doing instead

    Judge sides with Anthropic to temporarily block the Pentagon’s ban

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Terms & Conditions
    • Privacy Policy
    • Disclaimer

    © 2026 ainewstoday.co. All rights reserved. Designed by DD.

    Type above and press Enter to search. Press Esc to cancel.