Minacce e avversari · Supply chain

TeamPCP Ruba Segreti CI da Checkmarx GitHub Actions

TeamPCP ha usato credenziali rubate nella breach di Trivy del 19 marzo (CVE-2026-33634) per accedere ai workflow GitHub Actions di Checkmarx e esfiltrare segreti CI.

2 fonti · 24 mar

CVE-2026-33634

NVD KEV

Sfruttamento noto · CISA KEV

Data di correzione federale CISA 9 apr

Cronologia

Fonti

Part of the PlainSec briefing for 2026-03-26

Every edition of this story: TeamPCP Ruba Segreti CI da Checkmarx GitHub Actions

Altro da oggi