<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Checkmarx on Security Unlocked</title><link>https://securityunlocked.com/tags/checkmarx/</link><description>Recent content in Checkmarx on Security Unlocked</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 28 Apr 2026 17:00:00 +0000</lastBuildDate><atom:link href="https://securityunlocked.com/tags/checkmarx/index.xml" rel="self" type="application/rss+xml"/><item><title>When the Security Tool IS the Supply Chain Attack</title><link>https://securityunlocked.com/alerts/when-the-security-tool-is-the-supply-chain-attack/</link><pubDate>Tue, 28 Apr 2026 17:00:00 +0000</pubDate><guid>https://securityunlocked.com/alerts/when-the-security-tool-is-the-supply-chain-attack/</guid><description>TeamPCP&amp;rsquo;s supply-chain campaign has propagated from Trivy to Checkmarx KICS, Checkmarx GitHub Actions, two Open VSX plugins, and now Bitwarden CLI. Lapsus$ is handling the extortion. The blast radius now reaches a password manager with 10M+ users.</description></item></channel></rss>