New Checkmarx supply-chain breach affects KICS analysis tool

Hackers have compromised Docker images, VSCode and Open VSX extensions for the Checkmarx KICS analysis tool to harvest sensitive data from developer environments.

BleepingComputer
Bitwarden CLI has been compromised in a supply chain attack that targeted KICS. #bitwarden #kics #malware #supplychain https://socket.dev/blog/bitwarden-cli-compromised
Bitwarden CLI Compromised in Ongoing Checkmarx Supply Chain Campaign

Bitwarden CLI 2026.4.0 was compromised in the Checkmarx supply chain campaign after attackers abused a GitHub Action in Bitwarden’s CI/CD pipeline.

Socket

Checkmarx nel mirino di TeamPCP: l’immagine Docker ufficiale di KICS trojanizzata per esfiltrare i segreti dell’infrastruttura

Per la seconda volta in due mesi, il gruppo TeamPCP ha violato la supply chain di Checkmarx, pubblicando immagini Docker trojanizzate del security scanner KICS ed estensioni VS Code maligne capaci di rubare token cloud, credenziali GitHub e chiavi SSH. Il payload mcpAddon.js, consegnato tramite runtime Bun da un commit retrodatato, punta a trasformare ogni pipeline CI/CD in un punto di esfiltrazione.

https://insicurezzadigitale.com/checkmarx-nel-mirino-di-teampcp-limmagine-docker-ufficiale-di-kics-trojanizzata-per-esfiltrare-i-segreti-dellinfrastruttura/

Malicious Docker Images Compromise Checkmarx Supply Chain

Malicious Docker images compromised the Checkmarx supply chain by embedding a tampered KICS binary that secretly collected and sent sensitive data to an external endpoint. This sneaky data-exfiltration risk put users at risk, thanks to an altered scan report generated by the poisoned image.

https://osintsights.com/malicious-docker-images-compromise-checkmarx-supply-chain?utm_source=mastodon&utm_medium=social

#MaliciousDockerImages #SupplyChain #DockerHub #DataExfiltration #Kics

Malicious Docker Images Compromise Checkmarx Supply Chain

Learn how malicious Docker images compromised Checkmarx supply chain via altered KICS binary, and take steps to secure your software supply chain now effectively.

OSINTSights

Aqua Security’s Trivy GitHub Action was compromised, and Checkmarx’s KICS too: a reminder that I wrote an Actions audit script that can search for particular Actions and versions run in workflows (or just list all Actions with exact commit versions run in all workflows).

Auditing script:
https://github.com/github/audit-actions-workflow-runs

StepSecurity blogs in the thread 🧵

#Actions #SupplyChain #SCA #Malware #Trivy #KICS

GitHub - github/audit-actions-workflow-runs: Audit your GitHub Actions workflow runs to see exactly which Actions were downloaded

Audit your GitHub Actions workflow runs to see exactly which Actions were downloaded - github/audit-actions-workflow-runs

GitHub
South Korean insurers prioritize CEO reappointments and fundamental strengthening amid Middle East uncertainty, regulatory pressures, and market volatility, as authorities intensify scrutiny of actuarial practices and profitability metrics following IFRS17 implementation controversies.
#YonhapInfomax #InsuranceIndustry #CeoReappointment #KICS #IFRS17 #FinancialSoundness #Economics #FinancialMarkets #Banking #Securities #Bonds #StockMarket
https://en.infomaxai.com/news/articleView.html?idxno=109711
[Lee Yun-gu's Free Kicks] Insurance Industry Needs to Focus on 'Fundamentals' Now

South Korean insurers prioritize CEO reappointments and fundamental strengthening amid Middle East uncertainty, regulatory pressures, and market volatility, as authorities intensify scrutiny of actuarial practices and profitability metrics following IFRS17 implementation controversies.

Yonhap Infomax
iM Life is relocating its headquarters to secure liquidity and strengthen core operations, aiming to improve capital adequacy and financial stability amid upcoming regulatory changes.
#YonhapInfomax #IMLife #Liquidity #KICS #CapitalAdequacy #FinancialStability #Economics #FinancialMarkets #Banking #Securities #Bonds #StockMarket
https://en.infomaxai.com/news/articleView.html?idxno=106614
Hanwha Life Insurance missed its K-ICS capital adequacy target due to a larger-than-expected claims reserve gap, and plans to bolster core capital ratios ahead of new regulations.
#YonhapInfomax #HanwhaLife #KICS #CoreCapital #ClaimsReserveGap #DividendPolicy #Economics #FinancialMarkets #Banking #Securities #Bonds #StockMarket
https://en.infomaxai.com/news/articleView.html?idxno=106344
Hanwha Life Misses K-ICS Guidance Due to Claims Reserve Gap—Vows to Strengthen Core Capital

Hanwha Life Insurance missed its K-ICS capital adequacy guidance due to a larger-than-expected claims reserve gap, and plans to boost core capital ratios ahead of new regulations.

Yonhap Infomax
Samsung Life Insurance will continue to include gains from Samsung Electronics share sales in its dividend resources, aiming to steadily increase dividends while adapting to regulatory changes that reclassify policyholder equity as capital.
#YonhapInfomax #SamsungLifeInsurance #SamsungElectronics #DividendPolicy #KICS #EquityCapital #Economics #FinancialMarkets #Banking #Securities #Bonds #StockMarket
https://en.infomaxai.com/news/articleView.html?idxno=106011
Samsung Life to Include Gains from Samsung Electronics Share Sale in Dividend Resources

Samsung Life Insurance will continue to include gains from Samsung Electronics share sales in its dividend resources, aiming to steadily increase dividends while adapting to regulatory changes that reclassify policyholder equity as capital.

Yonhap Infomax
Samsung Life Insurance posted a 9.3% rise in 2025 net profit to 2.3 trillion won, maintaining its ‘2 Trillion Won Club’ status for a third year, driven by strong CSM growth and robust investment returns.
#YonhapInfomax #SamsungLifeInsurance #NetProfit #ContractualServiceMargin #KICS #HealthInsuranceProducts #Economics #FinancialMarkets #Banking #Securities #Bonds #StockMarket
https://en.infomaxai.com/news/articleView.html?idxno=106001
Samsung Life Reports 2.3 Trillion Won Net Profit for 2025, Up 9.3%—Joins ‘2 Trillion Won Club’ for Third Consecutive Year

Samsung Life Insurance posted a 9.3% rise in 2025 net profit to 2.3 trillion won, maintaining its ‘2 Trillion Won Club’ status for a third year, driven by strong CSM growth and robust investment returns.

Yonhap Infomax