Checkmarx KICS Actions Compromised
Checkmarx KICS, an open-source security scanner, was compromised in the TeamPCP campaign. Credentials from Trivy were used to attack its GitHub Actions.
Checkmarx KICS, an open-source security scanner, was compromised in the TeamPCP campaign. Credentials from Trivy were used to attack its GitHub Actions.
Trivy, an open-source security scanner, was compromised in March 2026. Credentials stolen from Trivy were used to compromise Checkmarx KICS actions.
skills.sh is a platform that integrates multiple security scanners for AI agent skills, all of which failed to detect AIR's fake skill…