Supply chain attacks hit Checkmarx and Bitwarden developer tools
2026-04-26T08:51:35Z•02df7ea18eb51338b31fa3609bb00156b730f60832baafbae8de4db5198ed446
AIAdobe ReaderCitrixBleed2LLMMicrosoft Patch TuesdayOpenClawPayoutsKingQEMUSophos Firewall v22bitwardencheckmarxcommand-and-controlpatchespipelineransomwaresupply-chainthreat-researchvirtual-machinevulnerability-floodzero-day
What happened
Sophos feed highlights multiple active and high-impact threats: same-day supply-chain compromises of developer tools impacting Checkmarx and Bitwarden (sharing a command-and-control domain); abuse of QEMU/hidden VMs to persist, harvest credentials, exfiltrate data and deliver PayoutsKing ransomware; an Adobe Reader zero-day in active exploitation; and Microsoft’s April Patch Tuesday addressing 163 CVEs. Other items include Sophos Firewall v22 MR1 release, a passkeys CISO playbook, Red Team/AI testing with OpenClaw, and commentary on accelerating AI-driven vulnerability discovery. Overall trend
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- 02df7ea18eb51338b31fa3609bb00156b730f60832baafbae8de4db5198ed446
- Enrichment time
- 2026-04-26T08:51:35Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.