Supply chain campaign has now extended to Checkmarx’s Jenkins ecosystem, with attackers pushing a malicious Checkmarx Jenkins AST plugin to the official Jenkins Marketplace as part of the ongoing KICS/Trivy-linked compromise. The rogue release is identified as version 2026.5.09 and includes tampered plugin artifacts, while the last known-good Jenkins AST plugin build remains 2.0.13-829.vc72453fa_1c16, released […]
The post Checkmarx Jenkins AST Plugin Compromised in KICS Supply Chain Attack appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.