CVE-2026-33634
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 9 apr
Minacce e avversari · Supply chain
TeamPCP ha usato credenziali rubate nella breach di Trivy del 19 marzo (CVE-2026-33634) per accedere ai workflow GitHub Actions di Checkmarx e esfiltrare segreti CI.
2 fonti · 24 mar
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 9 apr
The Hacker News
TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI Credentials
TeamPCP compromised 2 GitHub Actions post-March 19, 2026 breach, enabling credential theft and supply chain attacks.
originaleWiz Research
KICS GitHub Action Compromised: TeamPCP Supply Chain Attack | Wiz Blog
Checkmarx KICS Github Action hijacked by TeamPCP.
originalePart of the PlainSec briefing for 2026-03-26
Every edition of this story: TeamPCP Ruba Segreti CI da Checkmarx GitHub Actions