bleepingcomputer.com › news › security Official CheckMarx Jenkins package compromised with infostealer … A company spokesperson confirmed to BleepingComputer that the threat actor obtained credentials to the repositories from the Trivy supply-chain attack in March. … May 11, 2026 · Bill Toulas