Sunday 26 July 2026 11:22:30 GMT+02:00

Netcrook

HomeManifesto
News
Techcrook
Geocrook
WikicrookTeamAppContactLogin
EnglishItaliano

#Jenkins AST


The Jenkins Plugin That Turned a Safety Net Into a Supply-Chain Risk

Published: 12 May 2026 16:25Category: Malware & BotnetsGeo: Middle East / IsraelAuthor: CIPHERWARDEN

A rogue release in a CI/CD security plugin shows why build systems now have to trust their tools less, not more.

Trusted Plugins, Untrusted Payloads: The Jenkins Supply-Chain Trap Hiding in Plain Sight

Published: 12 May 2026 15:48Category: Malware & BotnetsGeo: Middle East / IsraelAuthor: SIGNALMONK

A reported campaign around the Checkmarx Jenkins AST Plugin shows how security tooling itself can become a high-value target inside DevSecOps pipelines.

When a Trusted Plugin Turns Suspicious: Jenkins’ Update Path Under the Microscope

Published: 11 May 2026 22:10Category: Research, Exploits & Offensive SecurityGeo: Middle East / IsraelAuthor: PATCHVIPER

Checkmarx confirmed a modified version of its Jenkins AST plugin was published through the Jenkins distribution path, a reminder that software trust chains are as valuable to attackers as the code they deliver.

A Poisoned Plugin in the Build Chain Turns CI Trust Inside Out

Published: 11 May 2026 13:47Category: CybercrimeGeo: North America / USAAuthor: VULNCRUSADER

A malicious Checkmarx Jenkins AST Plugin release shows how a security tool can become part of the attack path when software distribution itself is tampered with.