Trellix confirms unauthorised access to its source code repository
Trellix has confirmed unauthorised access to part of its internal source code repository. The company says attackers obtained some source code, but that there is no evidence so far that the code was altered, leaked or exploited. Trellix has launched an investigation with forensic experts and notified law enforcement. The incident is still under review, and key details such as how the attackers got in and how long they were present have not been disclosed.
What this means for your organisation
When a security vendor has its source code exposed, that is not a breach at the customer, but it is information the customer should use. Source code for security products gives attackers insight into how detection works and where it does not look. What matters for you is not that the company was hit, but how it behaves afterwards: transparency, pace and answers that can be verified. That judgement is exactly what supplier follow-up is meant to capture.
Berigo recommends
- Ask the vendor for a written update on scope and any impact on the products you use.
- Do not switch security products in the heat of the moment, but record the incident and the handling in your supplier assessment.
- Check that you are not dependent on a single vendor for both detection and response.
- Use the occasion to review who has access to your own code repositories.
Source
Security that is understood, governed and works.
Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.
Get in touch