• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
trellix confirms source code breach with unauthorized repository access

Trellix Confirms Source Code Breach With Unauthorized Repository Access

You are here: Home / General Cyber Security News / Trellix Confirms Source Code Breach With Unauthorized Repository Access
May 2, 2026

Cybersecurity company Trellix has announced that it suffered a breach that enabled unauthorized access to a “portion” of its source code.

It said it “recently identified” the compromise of its source code repository and that it began working with “leading forensic experts” to resolve the matter immediately. It also said it has notified law enforcement of the matter.

Trellix did not disclose the exact nature of the data that may have been accessed by the attackers. However, it pointed out that there are indications that its source code has been affected or exploited.

✔ Approved Seller From Our Partners
Mullvad VPN Discount

Protect your privacy by Mullvad VPN. Mullvad VPN is one of the famous brands in the security and privacy world. With Mullvad VPN you will not even be asked for your email address. No log policy, no data from you will be saved. Get your license key now from the official distributor of Mullvad with discount: SerialCart® (Limited Offer).

➤ Get Mullvad VPN with 12% Discount


Cybersecurity

“Based on our investigation to date, we have found no evidence that our source code release or distribution process was affected, or that our source code has been exploited,” the company added. 

The company did not share any details about who may be behind the incident, and for how long the attackers had access to its systems. Trellix noted that additional information will be shared as appropriate once its investigation is complete.

Owned by Symphony Technology Group, Trellix was founded in January 2022 following the merger of McAfee Enterprise and FireEye. Around the same time, Mandiant, which was owned by FireEye, was acquired by Google in a deal worth $5.4 billion.

The Hacker News has reached out to Trellix for comment, and we will update the story if we hear back.

(This is a developing story. Please check back for more details.)

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


Some parts of this article are sourced from:
thehackernews.com

Previous Post: «30,000 facebook accounts hacked via google appsheet phishing campaign 30,000 Facebook Accounts Hacked via Google AppSheet Phishing Campaign

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • Trellix Confirms Source Code Breach With Unauthorized Repository Access
  • 30,000 Facebook Accounts Hacked via Google AppSheet Phishing Campaign
  • Cybercrime Groups Using Vishing and SSO Abuse in Rapid SaaS Extortion Attacks
  • China-Linked Hackers Target Asian Governments, NATO State, Journalists, and Activists May 01, 2026 Vulnerability / Network Security Cybersecurity researchers have disclosed details of a new China-aligned espionage campaign targeting government and defense sectors across South, East, and Southeast Asia, along with one European government belonging to NATO. Trend Micro has attributed the activity to a threat activity cluster it tracks under the temporary designation SHADOW-EARTH-053 . The adversarial collective is assessed to be active since at least December 2024, while sharing some level of network overlap with CL-STA-0049, Earth Alux, and REF7707 . "The group exploits N-day vulnerabilities in internet-facing Microsoft Exchange and Internet Information Services (IIS) servers (e.g., ProxyLogon chain), then deploys web shells ( Godzilla ) for persistent access and stages ShadowPad implants via DLL sideloading of legitimate signed executables," security researchers Daniel Lunghi and Lucas Silva said in an analysis. Targets of the campaigns include Pakistan, Thailand, Malaysia, India, Myanmar, Sri Lank…
  • Top Five Sales Challenges Costing MSPs Cybersecurity Revenue
  • Two Cybersecurity Professionals Get 4-Year Sentences in BlackCat Ransomware Attacks
  • Poisoned Ruby Gems and Go Modules Exploit CI Pipelines for Credential Theft
  • PyTorch Lightning Compromised in PyPI Supply Chain Attack to Steal Credentials
  • ThreatsDay Bulletin: SMS Blaster Busts, OpenEMR Flaws, 600K Roblox Hacks and 25 More Stories
  • New Python Backdoor Uses Tunneling Service to Steal Browser and Cloud Credentials

Copyright © TheCyberSecurity.News, All Rights Reserved.