Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack

2026-04-28T01:24:11Z816679d16e65d44c0d0ed23b92d9712cb18c4bbc963aad73158bb70d8f9094e7
active-exploitationaptbackdoorbitwardencisa-kevcve-2024-57726cve-2026-28950cve-2026-33626dark-webdata-exposuredockerfirestartergithubglasswormgopherwhisperkicslmdeploymalicious-packagesnpmphantomcoressrfsupply-chaintropic-trooperunc6692','vulnerabilities','patch','apple','ios','fake-apps','phvs-code-extensions

What happened

Multiple high-impact supply-chain and active-exploitation incidents reported by The Hacker News. Checkmarx confirmed data from its GitHub repository was posted to the dark web following a March 23 supply-chain attack; related supply-chain compromises include malicious KICS Docker images, trojanized VS Code extensions (GlassWorm cluster), and a compromised Bitwarden CLI package tied to the ongoing Checkmarx campaign. Researchers also reported rapid exploitation of LMDeploy SSRF (CVE-2026-33626) within hours of disclosure, CISA additions to its Known Exploited Vulnerabilities (including CVE-2024

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
816679d16e65d44c0d0ed23b92d9712cb18c4bbc963aad73158bb70d8f9094e7
Enrichment time
2026-04-28T01:24:11Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Checkmarx Confirms GitHub Repository Data Posted on Dark Web After March 23 Attack · Baitaphish