Ticker feed
Day two of Pwn2Own Berlin 2026 saw hackers unleash devastating attacks on enterprise software and AI tools, adding $385,750 in bug bounties to bring the total to $908,750.
Orange Tsai from DEVCORE stole the show with a brutal Microsoft Exchange exploit, chaining three vulnerabilities to achieve remote code execution with SYSTEM privileges. The attack earned $200,000 and highlights Exchange's role as a critical enterprise target.
Security researchers also escalated privileges on Windows 11 through an integer overflow bug — worth $7,500, next to Exchange's $200,000 — and hit multiple AI coding platforms including Cursor IDE and OpenAI Codex. These AI tools are becoming prime targets due to their access to source code and developer workflows.
DEVCORE leads the competition on 40.5 Master of Pwn points and $405,000 in winnings, and the final day promises more zero-day discoveries. Every vendor now has 90 days to ship a fix before ZDI publishes the details.
Updated August 13, 2026: Pwn2Own Berlin closed on May 16 with $1,298,250 paid out for 47 zero-days, and DEVCORE took Master of Pwn on 50.5 points and $505,000.
Source: Cyber Security News
Day two of Pwn2Own Berlin 2026 saw hackers unleash devastating attacks on enterprise software and AI tools, adding $385,750 in bug bounties to bring the total to $908,750.
Orange Tsai from DEVCORE stole the show with a brutal Microsoft Exchange exploit, chaining three vulnerabilities to achieve remote code execution with SYSTEM privileges. The attack earned $200,000 and highlights Exchange's role as a critical enterprise target.
Security researchers also escalated privileges on Windows 11 through an integer overflow bug — worth $7,500, next to Exchange's $200,000 — and hit multiple AI coding platforms including Cursor IDE and OpenAI Codex. These AI tools are becoming prime targets due to their access to source code and developer workflows.
DEVCORE leads the competition on 40.5 Master of Pwn points and $405,000 in winnings, and the final day promises more zero-day discoveries. Every vendor now has 90 days to ship a fix before ZDI publishes the details.
Updated August 13, 2026: Pwn2Own Berlin closed on May 16 with $1,298,250 paid out for 47 zero-days, and DEVCORE took Master of Pwn on 50.5 points and $505,000.
Source: Cyber Security News
OpenAI disclosed that two employee devices in its corporate environment were infected during the May 11 TanStack supply chain attack, attributed by researchers to TeamPCP. The attackers exploited weaknesses in package publishing to release 84 malicious artifacts across 42 packages, carrying Mini Shai-Hulud — a variant of the Shai-Hulud worm.
Limited credential material was exfiltrated from a subset of internal source code repositories. OpenAI says it has found no evidence that user data, production systems or intellectual property were affected. It rotated all credentials across the impacted repositories and revoked user sessions.
Those repositories also held code-signing certificates for OpenAI's iOS, macOS and Windows products, which have now been rotated and the apps re-signed. Only macOS users need to act: update ChatGPT Desktop, the Codex app, Codex CLI and Atlas by June 12, 2026, or macOS will start blocking the older builds.
The 84 poisoned versions shipped with valid SLSA Build Level 3 provenance, so signed attestations were no defence. For OpenAI the timing was awkward — it was still hardening after a malicious Axios package reached it through a GitHub Actions workflow in late March.
Source: Security Week
OpenAI disclosed that two employee devices in its corporate environment were infected during the May 11 TanStack supply chain attack, attributed by researchers to TeamPCP. The attackers exploited weaknesses in package publishing to release 84 malicious artifacts across 42 packages, carrying Mini Shai-Hulud — a variant of the Shai-Hulud worm.
Limited credential material was exfiltrated from a subset of internal source code repositories. OpenAI says it has found no evidence that user data, production systems or intellectual property were affected. It rotated all credentials across the impacted repositories and revoked user sessions.
Those repositories also held code-signing certificates for OpenAI's iOS, macOS and Windows products, which have now been rotated and the apps re-signed. Only macOS users need to act: update ChatGPT Desktop, the Codex app, Codex CLI and Atlas by June 12, 2026, or macOS will start blocking the older builds.
The 84 poisoned versions shipped with valid SLSA Build Level 3 provenance, so signed attestations were no defence. For OpenAI the timing was awkward — it was still hardening after a malicious Axios package reached it through a GitHub Actions workflow in late March.
Source: Security Week
A threat actor Cisco Talos tracks as UAT-8616 is exploiting a critical authentication bypass (CVE-2026-20182, CVSS 10.0) in Cisco Catalyst SD-WAN Controller and SD-WAN Manager — formerly vSmart and vManage. Talos says exploitation has been limited so far and clusters it under UAT-8616 with high confidence. Unauthenticated attackers gain administrative access and NETCONF control over network configuration.
CISA added it to the KEV catalog the day it was disclosed and gave federal agencies until May 17 under Emergency Directive 26-03. Fixed releases are 20.9.9.1, 20.12.5.4, 20.12.6.2, 20.12.7.1, 20.15.4.4, 20.15.5.2, 20.18.2.2 and 26.1.1.1 — check which train you're on, since older releases need migrating rather than updating. There's no workaround.
It's at least the fifth Cisco SD-WAN flaw under active exploitation this year. UAT-8616 has been exploiting a nearly identical bypass, CVE-2026-20127, since at least 2023 — Cisco called that exploitation limited, Talos called it extensive. Ten further clusters, distinct from UAT-8616, have been hitting three more SD-WAN bypasses since March, dropping webshells, cryptominers and infostealers.
UAT-8616 targets critical infrastructure and other high-value organizations globally, and reaches root by an unusual route: downgrade the software, exploit the old CVE-2022-20775, then restore the original version. Talos notes the group's infrastructure overlaps with Operational Relay Box networks it monitors. Check auth.log for "Accepted publickey for vmanage-admin" from unfamiliar IPs.
Updated August 13, 2026: Cisco patched another actively exploited SD-WAN Manager flaw in June — CVE-2026-20262, an arbitrary file write rated 6.5, KEV-listed with a June 29 federal deadline. Its fixed releases supersede the May builds: 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1 and 26.1.1.2. By then it was the eighth exploited Cisco SD-WAN flaw of 2026.
Source: Dark Reading
A threat actor Cisco Talos tracks as UAT-8616 is exploiting a critical authentication bypass (CVE-2026-20182, CVSS 10.0) in Cisco Catalyst SD-WAN Controller and SD-WAN Manager — formerly vSmart and vManage. Talos says exploitation has been limited so far and clusters it under UAT-8616 with high confidence. Unauthenticated attackers gain administrative access and NETCONF control over network configuration.
CISA added it to the KEV catalog the day it was disclosed and gave federal agencies until May 17 under Emergency Directive 26-03. Fixed releases are 20.9.9.1, 20.12.5.4, 20.12.6.2, 20.12.7.1, 20.15.4.4, 20.15.5.2, 20.18.2.2 and 26.1.1.1 — check which train you're on, since older releases need migrating rather than updating. There's no workaround.
It's at least the fifth Cisco SD-WAN flaw under active exploitation this year. UAT-8616 has been exploiting a nearly identical bypass, CVE-2026-20127, since at least 2023 — Cisco called that exploitation limited, Talos called it extensive. Ten further clusters, distinct from UAT-8616, have been hitting three more SD-WAN bypasses since March, dropping webshells, cryptominers and infostealers.
UAT-8616 targets critical infrastructure and other high-value organizations globally, and reaches root by an unusual route: downgrade the software, exploit the old CVE-2022-20775, then restore the original version. Talos notes the group's infrastructure overlaps with Operational Relay Box networks it monitors. Check auth.log for "Accepted publickey for vmanage-admin" from unfamiliar IPs.
Updated August 13, 2026: Cisco patched another actively exploited SD-WAN Manager flaw in June — CVE-2026-20262, an arbitrary file write rated 6.5, KEV-listed with a June 29 federal deadline. Its fixed releases supersede the May builds: 20.9.9.2, 20.12.7.2, 20.15.4.5, 20.15.5.3, 20.18.3.1 and 26.1.1.2. By then it was the eighth exploited Cisco SD-WAN flaw of 2026.
Source: Dark Reading
Electronics giant Foxconn, Apple's primary iPhone assembler, confirmed a cyberattack disrupted its North American factories. The Nitrogen ransomware group claimed responsibility on its leak site, saying it took 8 terabytes across more than 11 million files, including confidential instructions, projects and drawings from Intel, Apple, Google, Dell, and Nvidia.
Foxconn hasn't confirmed ransomware or data theft either way. Its cybersecurity team implemented measures to keep production and delivery running, and it said affected factories were resuming normal production as of May 12 — without specifying when the attack occurred or which systems were compromised. None of the five named companies would comment.
Nitrogen surfaced in 2023 as a loader distributing ALPHV ransomware, built its own encryptor from leaked Conti code in 2024, and steals data before encrypting systems to maximize pressure on victims. Halcyon's Cynthia Kaiser doubts the haul: recent Nitrogen claims have arrived without a working file listing, which points to a group inflating numbers to push ransoms higher.
The Taiwan-based manufacturer operates factories across Mexico, Wisconsin, Ohio, Texas, Virginia, and Indiana.
Source: CyberScoop
Electronics giant Foxconn, Apple's primary iPhone assembler, confirmed a cyberattack disrupted its North American factories. The Nitrogen ransomware group claimed responsibility on its leak site, saying it took 8 terabytes across more than 11 million files, including confidential instructions, projects and drawings from Intel, Apple, Google, Dell, and Nvidia.
Foxconn hasn't confirmed ransomware or data theft either way. Its cybersecurity team implemented measures to keep production and delivery running, and it said affected factories were resuming normal production as of May 12 — without specifying when the attack occurred or which systems were compromised. None of the five named companies would comment.
Nitrogen surfaced in 2023 as a loader distributing ALPHV ransomware, built its own encryptor from leaked Conti code in 2024, and steals data before encrypting systems to maximize pressure on victims. Halcyon's Cynthia Kaiser doubts the haul: recent Nitrogen claims have arrived without a working file listing, which points to a group inflating numbers to push ransoms higher.
The Taiwan-based manufacturer operates factories across Mexico, Wisconsin, Ohio, Texas, Virginia, and Indiana.
Source: CyberScoop
A security researcher released two Windows zero-day exploits on GitHub on May 13, after a dispute with Microsoft over its handling of their earlier reports. The more serious, "YellowKey", uses a crafted folder on a USB stick or the EFI partition to bypass BitLocker on Windows 11 and Server 2022/2025 in minutes — with physical access.
The public exploit only works against TPM-only BitLocker, which auto-unlocks at boot; it fails against TPM+PIN. The researcher says he has a version that defeats PIN setups too and is withholding it. Windows 10 is unaffected — its recovery architecture differs.
The second exploit, "GreenPlasma", targets the CTFMON service, but the released code is deliberately incomplete — it triggers a UAC prompt by default and lacks the piece needed for a SYSTEM shell. The researcher left that to whoever wants it.
Microsoft says it's investigating and hasn't patched either. A BitLocker PIN plus a BIOS password, per Kevin Beaumont, is the practical mitigation. Treat it as urgent: this researcher's April drops, RedSun and UnDefend, were weaponized in real attacks within days, per Huntress.
Updated August 13, 2026: Microsoft patched YellowKey and GreenPlasma on June 9, 2026, in the same Patch Tuesday that fixed the researcher's MiniPlasma flaw.
Source: Cyber Security News
A security researcher released two Windows zero-day exploits on GitHub on May 13, after a dispute with Microsoft over its handling of their earlier reports. The more serious, "YellowKey", uses a crafted folder on a USB stick or the EFI partition to bypass BitLocker on Windows 11 and Server 2022/2025 in minutes — with physical access.
The public exploit only works against TPM-only BitLocker, which auto-unlocks at boot; it fails against TPM+PIN. The researcher says he has a version that defeats PIN setups too and is withholding it. Windows 10 is unaffected — its recovery architecture differs.
The second exploit, "GreenPlasma", targets the CTFMON service, but the released code is deliberately incomplete — it triggers a UAC prompt by default and lacks the piece needed for a SYSTEM shell. The researcher left that to whoever wants it.
Microsoft says it's investigating and hasn't patched either. A BitLocker PIN plus a BIOS password, per Kevin Beaumont, is the practical mitigation. Treat it as urgent: this researcher's April drops, RedSun and UnDefend, were weaponized in real attacks within days, per Huntress.
Updated August 13, 2026: Microsoft patched YellowKey and GreenPlasma on June 9, 2026, in the same Patch Tuesday that fixed the researcher's MiniPlasma flaw.
Source: Cyber Security News
A supply chain campaign called "mini Shai-Hulud" poisoned around 170 open-source packages on May 11 and 12, including TanStack's react-router, which has over 12 million weekly downloads. UiPath, Mistral AI and Guardrails AI packages were hit too, and this is not the first wave — earlier ones reached Trivy, Bitwarden and Checkmarx.
Two-factor authentication never came into it. The attackers poisoned a GitHub Actions cache and lifted an OIDC token out of the runner's memory to mint a valid npm publish token. The malicious releases then carried genuine provenance attestations, so they showed verified badges pointing at an attacker-controlled build.
The malware writes itself into Visual Studio Code and Claude Code config directories, so it outlives uninstalling the package, and it disguises stolen data as anonymous messaging traffic through the Session app.
TanStack tells anyone who installed an affected version to change every connected cloud, server and developer credential. Do it in the right order: Wiz warns that the malware's gh-token-monitor daemon must be removed first, because revoking tokens while it is still running triggers destructive wiping. Then clear out .vscode and .claude, and block git-tanstack.com.
Source: CyberScoop
A supply chain campaign called "mini Shai-Hulud" poisoned around 170 open-source packages on May 11 and 12, including TanStack's react-router, which has over 12 million weekly downloads. UiPath, Mistral AI and Guardrails AI packages were hit too, and this is not the first wave — earlier ones reached Trivy, Bitwarden and Checkmarx.
Two-factor authentication never came into it. The attackers poisoned a GitHub Actions cache and lifted an OIDC token out of the runner's memory to mint a valid npm publish token. The malicious releases then carried genuine provenance attestations, so they showed verified badges pointing at an attacker-controlled build.
The malware writes itself into Visual Studio Code and Claude Code config directories, so it outlives uninstalling the package, and it disguises stolen data as anonymous messaging traffic through the Session app.
TanStack tells anyone who installed an affected version to change every connected cloud, server and developer credential. Do it in the right order: Wiz warns that the malware's gh-token-monitor daemon must be removed first, because revoking tokens while it is still running triggers destructive wiping. Then clear out .vscode and .claude, and block git-tanstack.com.
Source: CyberScoop
Mini Shai-Hulud is back on npm. On May 11, 84 malicious versions of 42 @tanstack/* packages were published between 19:20 and 19:26 UTC (CVE-2026-45321, CVSS 9.6 Critical). It spread from there into packages from Mistral AI, UiPath and OpenSearch, and into PyPI.
Aikido counted 373 malicious package-version entries across 169 npm package names; Socket, tracking 84 TanStack artifacts, said the real figure was likely at least double its own count. The worm steals npm, GitHub, cloud and CI/CD credentials from developer machines and runners, then republishes itself.
The dangerous part is how it published: a pull_request_target misconfiguration, GitHub Actions cache poisoning, then reading the runner's memory to lift the in-memory OIDC token. That produced malicious packages carrying valid SLSA Build Level 3 provenance — the first npm worm known to do it. Provenance verification alone will not catch this.
Researchers attribute the wave to TeamPCP, which Google tracks as UNC6780, on shared code markers and the group's own claim of credit. But the fully weaponized worm went public on GitHub on the evening of May 12, so the toolchain is now available to anyone, and later waves won't attribute so cleanly.
Order matters when cleaning up. Kill the gh-token-monitor persistence service before rotating anything — revoking tokens first triggers a dead-man's switch that wipes the home directory. Then remove the injected hooks in .claude/ and .vscode/, rotate npm, GitHub and cloud credentials, DNS-block *.getsession.org, and audit publishing logs for releases nobody triggered.
Updated August 13, 2026: The worm resurfaced on June 19 with 1,614 exfiltration repositories tied to 21 compromised GitHub accounts — identity compromise rather than a software flaw, so no CVE and nothing for a vulnerability scanner to find. Researchers attribute that wave to TeamPCP with moderate confidence.
Source: Dark Reading
Mini Shai-Hulud is back on npm. On May 11, 84 malicious versions of 42 @tanstack/* packages were published between 19:20 and 19:26 UTC (CVE-2026-45321, CVSS 9.6 Critical). It spread from there into packages from Mistral AI, UiPath and OpenSearch, and into PyPI.
Aikido counted 373 malicious package-version entries across 169 npm package names; Socket, tracking 84 TanStack artifacts, said the real figure was likely at least double its own count. The worm steals npm, GitHub, cloud and CI/CD credentials from developer machines and runners, then republishes itself.
The dangerous part is how it published: a pull_request_target misconfiguration, GitHub Actions cache poisoning, then reading the runner's memory to lift the in-memory OIDC token. That produced malicious packages carrying valid SLSA Build Level 3 provenance — the first npm worm known to do it. Provenance verification alone will not catch this.
Researchers attribute the wave to TeamPCP, which Google tracks as UNC6780, on shared code markers and the group's own claim of credit. But the fully weaponized worm went public on GitHub on the evening of May 12, so the toolchain is now available to anyone, and later waves won't attribute so cleanly.
Order matters when cleaning up. Kill the gh-token-monitor persistence service before rotating anything — revoking tokens first triggers a dead-man's switch that wipes the home directory. Then remove the injected hooks in .claude/ and .vscode/, rotate npm, GitHub and cloud credentials, DNS-block *.getsession.org, and audit publishing logs for releases nobody triggered.
Updated August 13, 2026: The worm resurfaced on June 19 with 1,614 exfiltration repositories tied to 21 compromised GitHub accounts — identity compromise rather than a software flaw, so no CVE and nothing for a vulnerability scanner to find. Researchers attribute that wave to TeamPCP with moderate confidence.
Source: Dark Reading
TeamPCP hackers compromised over 170 packages across major software projects on May 11, including 42 TanStack packages, 65 UiPath packages, and Mistral AI's PyPI packages.
The "Mini Shai-Hulud" attack chained three weaknesses in TanStack's GitHub Actions — ending with an OIDC token lifted straight out of runner memory — to hijack the pipeline and publish malicious packages carrying valid SLSA provenance. Tenable tracks the chain as CVE-2026-45321, CVSS 9.6. Provenance proves which pipeline built a package, not that the pipeline was behaving.
The malware steals developer credentials, API keys, cryptocurrency wallets, and cloud secrets, and spreads by using stolen tokens to publish infected versions of other packages. For the first time, its Python variant went after password managers including 1Password and Bitwarden, and it used the decentralized Session network for harder-to-disrupt exfiltration.
Check for compromised versions and audit your GitHub Actions configuration — then clean up in the right order. The malware runs a daemon that polls GitHub every minute to see whether its stolen token has been revoked, and revocation triggers a destructive wipe. Isolate and image the machine first, clear the persistence it leaves behind in .claude and .vscode, and rotate credentials after that.
Source: SecurityWeek
TeamPCP hackers compromised over 170 packages across major software projects on May 11, including 42 TanStack packages, 65 UiPath packages, and Mistral AI's PyPI packages.
The "Mini Shai-Hulud" attack chained three weaknesses in TanStack's GitHub Actions — ending with an OIDC token lifted straight out of runner memory — to hijack the pipeline and publish malicious packages carrying valid SLSA provenance. Tenable tracks the chain as CVE-2026-45321, CVSS 9.6. Provenance proves which pipeline built a package, not that the pipeline was behaving.
The malware steals developer credentials, API keys, cryptocurrency wallets, and cloud secrets, and spreads by using stolen tokens to publish infected versions of other packages. For the first time, its Python variant went after password managers including 1Password and Bitwarden, and it used the decentralized Session network for harder-to-disrupt exfiltration.
Check for compromised versions and audit your GitHub Actions configuration — then clean up in the right order. The malware runs a daemon that polls GitHub every minute to see whether its stolen token has been revoked, and revocation triggers a destructive wipe. Isolate and image the machine first, clear the persistence it leaves behind in .claude and .vscode, and rotate credentials after that.
Source: SecurityWeek
The exploit was real, and the plan was mass exploitation. A criminal group built it with AI help; Google's Threat Intelligence Group found it first, worked with the vendor on a fix, and disrupted the operation before it ran. Neither the group nor the tool, a popular open-source web administration platform, has been named.
The Python script bypassed 2FA — it needs valid credentials to start — by exploiting a hardcoded trust assumption in the enforcement logic, the kind of semantic flaw scanners miss. GTIG has high confidence an AI model helped: educational docstrings, textbook Pythonic structure, a hallucinated CVSS score. It doesn't believe Gemini was used.
State actors are scaling the same approach: China's UNC2814 posed as a binary security expert to get Gemini auditing TP-Link firmware, and North Korea's APT45 fired thousands of recursive prompts at CVEs and PoC exploits. GTIG notes frontier models still struggle with complex enterprise authorization logic.
PROMPTSPY is the sharper end: an Android backdoor that reads the on-screen UI, sends it to gemini-2.5-flash-lite, and acts on the JSON commands it gets back — clicking and swiping through the device unsupervised. No PROMPTSPY apps reached Google Play, and Play Protect covers known versions.
Russian operators padded CANFAIL and LONGSTREAM with LLM-written decoy code — 32 daylight-saving queries in one downloader — so malware reads as benign. TeamPCP monetised credentials stolen via SANDCLOCK through ransomware partnerships. Google disabled the accounts involved; the Big Sleep agent found the flaw in time, and CodeMender, which proposes fixes, is still experimental.
Source: Cybersecurity News
The exploit was real, and the plan was mass exploitation. A criminal group built it with AI help; Google's Threat Intelligence Group found it first, worked with the vendor on a fix, and disrupted the operation before it ran. Neither the group nor the tool, a popular open-source web administration platform, has been named.
The Python script bypassed 2FA — it needs valid credentials to start — by exploiting a hardcoded trust assumption in the enforcement logic, the kind of semantic flaw scanners miss. GTIG has high confidence an AI model helped: educational docstrings, textbook Pythonic structure, a hallucinated CVSS score. It doesn't believe Gemini was used.
State actors are scaling the same approach: China's UNC2814 posed as a binary security expert to get Gemini auditing TP-Link firmware, and North Korea's APT45 fired thousands of recursive prompts at CVEs and PoC exploits. GTIG notes frontier models still struggle with complex enterprise authorization logic.
PROMPTSPY is the sharper end: an Android backdoor that reads the on-screen UI, sends it to gemini-2.5-flash-lite, and acts on the JSON commands it gets back — clicking and swiping through the device unsupervised. No PROMPTSPY apps reached Google Play, and Play Protect covers known versions.
Russian operators padded CANFAIL and LONGSTREAM with LLM-written decoy code — 32 daylight-saving queries in one downloader — so malware reads as benign. TeamPCP monetised credentials stolen via SANDCLOCK through ransomware partnerships. Google disabled the accounts involved; the Big Sleep agent found the flaw in time, and CodeMender, which proposes fixes, is still experimental.
Source: Cybersecurity News
Checkmarx warned users on May 9 that hackers had published a malicious version of its Jenkins AST plugin — 2026.5.09 — to the Jenkins Marketplace. The plugin, which wires Checkmarx One scanning into Jenkins pipelines, carried a stealer going after crypto wallets, VPN configs, and AWS and GitHub credentials on Windows, Linux and macOS.
The company told users to fall back to version 2.0.13-829.vc72453fa_1c16 from December 2025, then released two newer builds over the weekend; 2.0.13-848.v76e89de8a_053 is now on GitHub and the Jenkins Marketplace. Updating isn't enough on its own — Checkmarx says to rotate every secret its CI runners could reach, from GitHub tokens to cloud and Kubernetes credentials.
The compromise traces back to March's Trivy supply chain attack, which handed TeamPCP the credentials to reach Checkmarx's GitHub repositories. Malicious artifacts followed in late March and again on April 22, and Checkmarx says LAPSUS$ published the stolen data on April 25.
Updated August 13, 2026: Mandiant confirmed the incident contained on June 4, and Checkmarx announced its investigation complete on July 6.
Source: Security Week
Checkmarx warned users on May 9 that hackers had published a malicious version of its Jenkins AST plugin — 2026.5.09 — to the Jenkins Marketplace. The plugin, which wires Checkmarx One scanning into Jenkins pipelines, carried a stealer going after crypto wallets, VPN configs, and AWS and GitHub credentials on Windows, Linux and macOS.
The company told users to fall back to version 2.0.13-829.vc72453fa_1c16 from December 2025, then released two newer builds over the weekend; 2.0.13-848.v76e89de8a_053 is now on GitHub and the Jenkins Marketplace. Updating isn't enough on its own — Checkmarx says to rotate every secret its CI runners could reach, from GitHub tokens to cloud and Kubernetes credentials.
The compromise traces back to March's Trivy supply chain attack, which handed TeamPCP the credentials to reach Checkmarx's GitHub repositories. Malicious artifacts followed in late March and again on April 22, and Checkmarx says LAPSUS$ published the stolen data on April 25.
Updated August 13, 2026: Mandiant confirmed the incident contained on June 4, and Checkmarx announced its investigation complete on July 6.
Source: Security Week