#checkmarx


Official CheckMarx Jenkins package compromised with infostealer

May 12, 2026 // 01:16

Checkmarx warned over the weekend that a rogue version of its Jenkins Application Security Testing (AST) plugin had been published on the Jenkins Marketplace. The […]

TeamPCP Compromises Checkmarx Jenkins AST Plugin Weeks After KICS Supply Chain Attack

May 12, 2026 // 00:07

Checkmarx has confirmed that a modified version of the Jenkins AST plugin was published to the Jenkins Marketplace. “If you are using Checkmarx Jenkins AST […]

Checkmarx confirms LAPSUS$ hackers leaked its stolen GitHub data

Apr 28, 2026 // 19:17

Application security company Checkmarx has confirmed that the LAPSUS$ threat group leaked data stolen from its private GitHub repository. Although the investigation is ongoing, Checkmarx […]

Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack

Apr 27, 2026 // 19:48

Checkmarx has disclosed that its ongoing investigation tied to the supply chain security incident has revealed that a cybercriminal group published data related to the […]

New Checkmarx supply-chain breach affects KICS analysis tool

Apr 23, 2026 // 20:17

Hackers have compromised Docker images, VSCode and Open VSX extensions for the Checkmarx KICS analysis tool to harvest sensitive data from developer environments. KICS, short […]

Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign

Apr 23, 2026 // 16:49

Bitwarden CLI has been compromised as part of the newly discovered and ongoing Checkmarx supply chain campaign, according to new findings from Socket. “The affected […]

Malicious KICS Docker Images and VS Code Extensions Hit Checkmarx Supply Chain

Apr 22, 2026 // 21:00

Cybersecurity researchers have warned of malicious images pushed to the official “checkmarx/kics” Docker Hub repository. In an alert published today, software supply chain security company […]

TeamPCP compromised Checkmarx GitHub Actions. Stolen credentials let them hack CI/CD.

Mar 24, 2026 // 12:33

TeamPCP, the same cybercriminals behind the Trivy supply chain attack, have compromised two more GitHub Actions workflows to steal credentials. These workflows, both from the […]