Supply Chain Attack at Application Security Testing Platform Provider Checkmarx
INCIDENT
Application security testing (AppSec) platform provider Checkmarx experienced a cybersecurity supply chain incident in March affecting certain developer artifacts distributed through third-party channels and it is continuing supplying updates to the incident.
Checkmarx is an enterprise-grade AppSec platform designed to help developers and security teams identify and remediate vulnerabilities in their code. It seamlessly integrates into developer workflows and CI/CD pipelines to secure software from early coding stages through to production.
The attack all unfolded on March 23 when Checkmarx discovered attackers gained unauthorized access to its GitHub repositories. This access occurred on March 19 due to the Trivy Supply Chain Attack.
