S

EPISODE · May 11, 2026 · 0 MIN

Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack

from Security Stuff · host Trace3

Cybersecurity firm Checkmarx has warned that a malicious version of its Jenkins AST plugin was published to the Jenkins Marketplace as part of an ongoing supply chain attack. The incident stems from a security breach that began in March when the TeamPCP hacker gang accessed Checkmarx's repositories through a separate Trivy supply chain attack, later followed by data exposure from the Lapsus dollar extortion group. Checkmarx has since released an updated, clean version of the plugin and is urging users to ensure they're running the latest secure iteration available on both GitHub and the Jenkins Marketplace.

Episode metadata supplied by the publisher feed · Published May 11, 2026

Embed this episode

NOW PLAYING

Checkmarx Jenkins AST Plugin Compromised in Supply Chain Attack

0:00 0:37

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of Security Stuff?

This episode is 0 minutes long.

When was this Security Stuff episode published?

This episode was published on May 11, 2026.

Can I download this Security Stuff episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!