Home / Companies / Semgrep / Blog / Post Details
Content Deep Dive

Attackers Are Still Coming for Security Companies. Here's Where We Stand.

Blog post from Semgrep

Post Details
Company
Date Published
Author
Katie Paxton-Fear
Word Count
1,529
Company Posts That Month
14
Language
English
Hacker News Points
-
Post removed?
No
Summary

The TeamPCP campaign highlights the persistent challenge of supply chain security in the software industry, affecting reputable organizations like Trivy, Checkmarx, and Bitwarden despite their strong security measures. Beginning in February, attackers exploited a common CI vulnerability, a misconfiguration in GitHub Actions workflows, to gain unauthorized access and expand their reach by compromising various platforms, including npm packages, Docker Hub, and VS Code extensions. The attackers used stolen credentials to infiltrate CI/CD pipelines, with significant incidents involving malicious code injection that harvested sensitive data. The campaign underscores the importance of structural controls, such as pinning GitHub Actions to immutable SHAs and implementing package cooldowns, to mitigate risks. Security teams are advised to scrutinize their CI environments and credential access points to better prepare against potential breaches, as the campaign continues to evolve with no clear end in sight.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Secrets Management 3 1,821 338 111 +22%
Kubernetes 1 2,306 381 103 +25%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.