New #Checkmarx supply-chain breach affects #KICS analysis tool
New #Checkmarx supply-chain breach affects #KICS analysis tool
Checkmarx nel mirino di TeamPCP: l’immagine Docker ufficiale di KICS trojanizzata per esfiltrare i segreti dell’infrastruttura
Per la seconda volta in due mesi, il gruppo TeamPCP ha violato la supply chain di Checkmarx, pubblicando immagini Docker trojanizzate del security scanner KICS ed estensioni VS Code maligne capaci di rubare token cloud, credenziali GitHub e chiavi SSH. Il payload mcpAddon.js, consegnato tramite runtime Bun da un commit retrodatato, punta a trasformare ogni pipeline CI/CD in un punto di esfiltrazione.Malicious Docker Images Compromise Checkmarx Supply Chain
Malicious Docker images compromised the Checkmarx supply chain by embedding a tampered KICS binary that secretly collected and sent sensitive data to an external endpoint. This sneaky data-exfiltration risk put users at risk, thanks to an altered scan report generated by the poisoned image.
#MaliciousDockerImages #SupplyChain #DockerHub #DataExfiltration #Kics
Aqua Security’s Trivy GitHub Action was compromised, and Checkmarx’s KICS too: a reminder that I wrote an Actions audit script that can search for particular Actions and versions run in workflows (or just list all Actions with exact commit versions run in all workflows).
Auditing script:
https://github.com/github/audit-actions-workflow-runs
StepSecurity blogs in the thread 🧵

South Korean insurers prioritize CEO reappointments and fundamental strengthening amid Middle East uncertainty, regulatory pressures, and market volatility, as authorities intensify scrutiny of actuarial practices and profitability metrics following IFRS17 implementation controversies.

Samsung Life Insurance will continue to include gains from Samsung Electronics share sales in its dividend resources, aiming to steadily increase dividends while adapting to regulatory changes that reclassify policyholder equity as capital.

Samsung Life Insurance posted a 9.3% rise in 2025 net profit to 2.3 trillion won, maintaining its ‘2 Trillion Won Club’ status for a third year, driven by strong CSM growth and robust investment returns.