Supply chain attacks hit Checkmarx and Bitwarden developer tools

2026-04-26T08:51:35Z02df7ea18eb51338b31fa3609bb00156b730f60832baafbae8de4db5198ed446
AIAdobe ReaderCitrixBleed2LLMMicrosoft Patch TuesdayOpenClawPayoutsKingQEMUSophos Firewall v22bitwardencheckmarxcommand-and-controlpatchespipelineransomwaresupply-chainthreat-researchvirtual-machinevulnerability-floodzero-day

What happened

Sophos feed highlights multiple active and high-impact threats: same-day supply-chain compromises of developer tools impacting Checkmarx and Bitwarden (sharing a command-and-control domain); abuse of QEMU/hidden VMs to persist, harvest credentials, exfiltrate data and deliver PayoutsKing ransomware; an Adobe Reader zero-day in active exploitation; and Microsoft’s April Patch Tuesday addressing 163 CVEs. Other items include Sophos Firewall v22 MR1 release, a passkeys CISO playbook, Red Team/AI testing with OpenClaw, and commentary on accelerating AI-driven vulnerability discovery. Overall trend

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
02df7ea18eb51338b31fa3609bb00156b730f60832baafbae8de4db5198ed446
Enrichment time
2026-04-26T08:51:35Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.