ctipilot.ch
← Back to Weekly 2026-W19
NOTABLEincident

Trellix source code repository breach — vendor confirmed, scope undisclosed, supply-chain integrity question open

discovered 2026-05-04 05:00 UTCrun 2026-W19-a5788b222 sourcesmulti-source

Trellix, a major endpoint-security / XDR vendor serving enterprise and government customers globally, confirmed on 2026-05-04 that an unauthorised party accessed a portion of its internal source code repository. The company engaged external forensic specialists and notified law enforcement; Trellix stated no evidence was found that its product code-release or distribution pipeline was affected and no evidence the accessed code was exploited or altered. The initial access vector, duration of access, scope of repositories affected, and customer data impact have not been disclosed (BleepingComputer, 2026-05-04 · The Hacker News, 2026-05-04 · daily 2026-05-06).

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.