CVE-2026-33634
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 9 apr
Minacce · 189 giorni fa
TeamPCP ha usato credenziali rubate nella breach di Trivy del 19 marzo (CVE-2026-33634) per accedere ai workflow GitHub Actions di Checkmarx e esfiltrare segreti CI.
Sfruttamento noto · CISA KEV
Data di correzione federale CISA 9 apr
2 fonti che coprono questa storia
TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI Credentials
TeamPCP compromised 2 GitHub Actions post-March 19, 2026 breach, enabling credential theft and supply chain attacks.
KICS GitHub Action Compromised: TeamPCP Supply Chain Attack | Wiz Blog
Checkmarx KICS Github Action hijacked by TeamPCP.
Part of the PlainSec briefing for 2026-03-26