Why a recent supply-chain attack singled out security firms Checkmarx and Bitwarden
2026-04-29T20:51:58Z•19eaa4d408131f6c61bba98a30e13ad11f9cbb58ede0e89ba53b29be2b6714ab
PQCai-vuln-discoveryaspnetcredential-theftcritical-infrastructuredata-exfiltrationelement-dataemergency-patchfirefoxgpu-exploitiranmalicious-packagemicrosoftnation-statenpmnvidiaopen-sourcepost-quantum-cryptographyquantum-threatransomwarerouter-compromiserowhammerrussiasoftware-supply-chainsupply-chain
What happened
Aggregation of multiple high-impact security stories in April 2026: a targeted supply-chain compromise hitting security firms (Checkmarx, Bitwarden); an npm/open-source package (element-data) exfiltrating credentials; a high-volume credential-theft campaign and widespread router compromises attributed to Russia; Iran-linked attacks disrupting US critical infrastructure and a maritime crypto-scam tied to a ship attack; new GPU Rowhammer variants (GDDRHammer/GeForge/GPUBreach) enabling full system compromise on machines with Nvidia GPUs; ransomware families experimenting with post‑quantum crypts
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- 19eaa4d408131f6c61bba98a30e13ad11f9cbb58ede0e89ba53b29be2b6714ab
- Enrichment time
- 2026-04-29T20:51:58Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.