2026-05-04 · view entry permalink →
NOTABLE
Trellix source code repository breach — vendor confirmed, scope undisclosed, supply-chain integrity question open
Trellix, a major endpoint-security / XDR vendor serving enterprise and government customers globally, confirmed on 2026-05-04 that an unauthorised party accessed a portion of its internal source code repository. The company engaged external forensic specialists and notified law enforcement; Trellix stated no evidence was found that its product code-release or distribution pipeline was affected and no evidence the accessed code was exploited or altered. The initial access vector, duration of access, scope of repositories affected, and customer data impact have not been disclosed (BleepingComputer, 2026-05-04 · The Hacker News, 2026-05-04 · daily 2026-05-06).