Rapid7 says attackers accessed some of its source code using a previously compromised Bash Uploader script from Codecov. An unknown number of Rapid7 customers are the latest victims of security incidents affecting trusted third-party software supply chain partners. Rapid7 is the latest in a string of companies to be severely impacted by security supply chain-related attacks, says Pathlock president of security analyst Kevin Dunne. Whitehat Security analyst: “Security vendors are often high-value targets, as they have deep, trusted access to networks that can provide an effective Trojan horse””]

