A supply chain attack has compromised Checkmarx’s KICS tool, poisoning Docker images and tampering with VS Code extensions to steal credentials and sensitive data from CI/CD pipelines. This highlights the growing risk of attackers targeting trusted development tools to gain access across multiple environments, emphasizing the need for robust security measures in software supply chains.
Read the full article at eSecurityPlanet
Want to create content about this topic? Use Nemati AI tools to generate articles, social posts, and more.





