<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #Checkmarx</title><description>Cybersecurity articles tagged #Checkmarx on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Malicious JetBrains Plugins Steal AI API Keys: Supply Chain Risks</title><link>https://runtimerebel.com/blog/malicious-jetbrains-plugins-steal-ai-api-keys-supply-chain-risks</link><guid isPermaLink="true">https://runtimerebel.com/blog/malicious-jetbrains-plugins-steal-ai-api-keys-supply-chain-risks</guid><description>Researchers discovered 15 malicious plugins on the JetBrains Marketplace designed to exfiltrate sensitive AI API keys from developers&apos; IDE environments.</description><pubDate>Wed, 17 Jun 2026 01:06:50 GMT</pubDate><category>JetBrains</category><category>API Theft</category><category>AI Security</category><category>Checkmarx</category><category>IDE Security</category></item><item><title>Checkmarx Jenkins AST Plugin Compromised in TeamPCP Attack</title><link>https://runtimerebel.com/blog/checkmarx-jenkins-ast-plugin-compromised-in-teampcp-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/checkmarx-jenkins-ast-plugin-compromised-in-teampcp-attack</guid><description>TeamPCP compromised the Checkmarx Jenkins AST plugin on the Jenkins Marketplace. Defenders must revert to version 2.0.13 to secure CI/CD pipelines.</description><pubDate>Mon, 11 May 2026 20:39:30 GMT</pubDate><category>Checkmarx</category><category>Jenkins</category><category>TeamPCP</category><category>Supply Chain Attack</category><category>CI CD Security</category></item><item><title>Checkmarx Supply Chain Attack: GitHub Data Exfiltration Confirmed</title><link>https://runtimerebel.com/blog/checkmarx-supply-chain-attack-github-data-exfiltration-confirmed</link><guid isPermaLink="true">https://runtimerebel.com/blog/checkmarx-supply-chain-attack-github-data-exfiltration-confirmed</guid><description>Checkmarx confirms data exfiltration from its GitHub environment following a malicious code publication. Learn about the TTPs and mitigation strategies.</description><pubDate>Wed, 29 Apr 2026 12:42:21 GMT</pubDate><category>Checkmarx</category><category>GitHub</category><category>Supply Chain Attack</category><category>Data Breach</category><category>Malicious Packages</category></item><item><title>Checkmarx Data Leak: LAPSUS$ Group Targets GitHub Repositories</title><link>https://runtimerebel.com/blog/checkmarx-data-leak-lapsus-group-targets-github-repositories</link><guid isPermaLink="true">https://runtimerebel.com/blog/checkmarx-data-leak-lapsus-group-targets-github-repositories</guid><description>LAPSUS$ threat actors leaked source code stolen from Checkmarx&apos;s private GitHub repositories. Analyze the impact of this supply chain security incident.</description><pubDate>Tue, 28 Apr 2026 16:42:35 GMT</pubDate><category>Lapsus Group</category><category>Checkmarx</category><category>Github Leak</category><category>Source Code Theft</category><category>Extortion</category></item><item><title>GlassWorm Malware: Cloned Open VSX Extensions Target Developers</title><link>https://runtimerebel.com/blog/glassworm-malware-cloned-open-vsx-extensions-target-developers</link><guid isPermaLink="true">https://runtimerebel.com/blog/glassworm-malware-cloned-open-vsx-extensions-target-developers</guid><description>Over 70 malicious Open VSX extensions cloned from popular tools deliver GlassWorm malware, highlighting risks in developer-focused supply chain attacks.</description><pubDate>Tue, 28 Apr 2026 12:45:16 GMT</pubDate><category>Open VSX</category><category>GlassWorm</category><category>VS Code</category><category>Checkmarx</category><category>Malware</category><category>Supply Chain Attack</category></item><item><title>Checkmarx GitHub Repository Data Leaked Following Supply Chain Attack</title><link>https://runtimerebel.com/blog/checkmarx-github-repository-data-leaked-following-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/checkmarx-github-repository-data-leaked-following-supply-chain-attack</guid><description>Checkmarx confirms internal GitHub repository data was published on the dark web following a March 2026 supply chain incident. Learn the impact and TTPs.</description><pubDate>Mon, 27 Apr 2026 16:37:34 GMT</pubDate><category>Checkmarx</category><category>GitHub</category><category>Supply Chain Attack</category><category>Data Leak</category><category>DevSecOps</category></item><item><title>Compromised Checkmarx KICS: Supply Chain Attack on Developer Environments</title><link>https://runtimerebel.com/blog/compromised-checkmarx-kics-supply-chain-attack-on-developer-environments</link><guid isPermaLink="true">https://runtimerebel.com/blog/compromised-checkmarx-kics-supply-chain-attack-on-developer-environments</guid><description>A supply chain attack compromised Checkmarx KICS Docker images and extensions, exposing developer environments to sensitive data theft. Learn mitigation.</description><pubDate>Thu, 23 Apr 2026 16:40:50 GMT</pubDate><category>Checkmarx</category><category>KICS</category><category>Supply Chain Attack</category><category>Developer Tools</category><category>VS Code</category><category>Docker</category><category>Data Theft</category></item><item><title>Checkmarx KICS Docker Repository and VS Code Extension Hijacked</title><link>https://runtimerebel.com/blog/checkmarx-kics-docker-repository-and-vs-code-extension-hijacked</link><guid isPermaLink="true">https://runtimerebel.com/blog/checkmarx-kics-docker-repository-and-vs-code-extension-hijacked</guid><description>Unknown threat actors hijacked the checkmarx/kics Docker Hub repository, overwriting official image tags to distribute malicious code via supply chain.</description><pubDate>Wed, 22 Apr 2026 20:24:25 GMT</pubDate><category>Checkmarx</category><category>KICS</category><category>Docker Hub Security</category><category>Supply Chain Attack</category><category>Socket Security</category></item><item><title>TeamPCP Supply Chain: Checkmarx Wider Scope &amp; LiteLLM PyPI Compromise</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-checkmarx-wider-scope-litellm-pypi-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-checkmarx-wider-scope-litellm-pypi-compromise</guid><description>An update on the TeamPCP supply chain campaign details wider Checkmarx impact, LiteLLM PyPI compromise, and a CISA KEV entry.</description><pubDate>Thu, 26 Mar 2026 20:16:14 GMT</pubDate><category>TeamPCP</category><category>Supply Chain Attack</category><category>Checkmarx</category><category>LiteLLM</category><category>PyPI</category><category>CISA KEV</category></item></channel></rss>