Established 2026Monday, 20 July 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageDevSecOps Desk
DevSecOps

Official CheckMarx Jenkins package compromised with infostealer

Official marketplace compromise demonstrates supply chain risks even for established security vendors, potentially exposing CI/CD pipelines to credential theft during security scans.

Summary written by editorial AI · Source link below

Filed by BleepingComputer1 min readRead at source ↗

Checkmarx warned over the weekend that a rogue version of its Jenkins Application Security Testing (AST) plugin had been published on the Jenkins Marketplace. [...]

Continue at the source
Read the full report at BleepingComputer

External link — opens at BleepingComputer in a new tab.

§
Continue with

More from the DevSecOps Desk