#actions


TeamPCP compromised Checkmarx GitHub Actions. Stolen credentials let them hack CI/CD.

Mar 24, 2026 // 12:33

TeamPCP, the same cybercriminals behind the Trivy supply chain attack, have compromised two more GitHub Actions workflows to steal credentials. These workflows, both from the […]

Trivy security flaw exploited: GitHub Actions pushed info-stealing malware.

Mar 22, 2026 // 14:37

The security tool Trivy was targeted in a supply-chain attack by a group called TeamPCP. They spread malware that steals credentials through official releases and […]

Here are five critical actions Chief Information Security Officers (CISOs) should prioritize now to safeguard AI agents.

Mar 17, 2026 // 21:14

By Itamar Apelblat, Founder and CEO, Token Security AI agents that can act independently are a game changer for businesses. These aren’t just improved chatbots […]