In the last month and a half, Checkmarx has encountered significant security challenges, including a supply-chain attack that compromised its systems. This incident began on March 19 when the vulnerability scanner Trivy was targeted. Hackers accessed Trivy’s GitHub account, enabling them to distribute malware to users, including Checkmarx. The malicious software was designed to extract sensitive information such as repository tokens and SSH keys from infected devices. Shortly after, Checkmarx itself fell victim to a breach of its GitHub account, which allowed attackers to send malware to its clients. Although Checkmarx attempted to address the situation by removing the malicious code and restoring legitimate applications, the company’s troubles did not end there, as it soon faced a ransomware attack from notorious cybercriminals. This series of events highlights the vulnerabilities that even established security firms can face in the ever-evolving landscape of cyber threats.
Recent Supply-Chain Attack Targets Security Firms Checkmarx and Bitwarden
Checkmarx faces a challenging period after suffering multiple cyberattacks, including a recent ransomware incident.
