#repository-compromise

[ follow ]
Information security
fromSecurityWeek
2 days ago

Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack

A modified Checkmarx Jenkins AST plugin was published via the Jenkins Marketplace, prompting users to update to a safe version. Supply-chain compromise traces to prior repository access.
Information security
fromThe Hacker News
2 months ago

Microsoft Warns Developers of Fake Next.js Job Repos Delivering In-Memory Malware

A coordinated campaign uses fake Next.js repositories and job assessment lures to trick developers into executing malicious code that establishes persistent command-and-control access.
[ Load more ]