A rogue release in a CI/CD security plugin shows why build systems now have to trust their tools less, not more.
A reported campaign around the Checkmarx Jenkins AST Plugin shows how security tooling itself can become a high-value target inside DevSecOps pipelines.
Checkmarx confirmed a modified version of its Jenkins AST plugin was published through the Jenkins distribution path, a reminder that software trust chains are as valuable to attackers as the code they deliver.
A malicious Checkmarx Jenkins AST Plugin release shows how a security tool can become part of the attack path when software distribution itself is tampered with.