Security vendor Trellix confirms attackers accessed its source code
Trellix, the cybersecurity company formed from the 2022 merger of McAfee Enterprise and FireEye, has disclosed that attackers gained unauthorized access to a portion of its internal source code repository.
The company said it “recently identified” the compromise and immediately brought in outside forensic investigators. Law enforcement has been notified.
According to Trellix’s official statement, the investigation so far has found no evidence that:
- The source code release or distribution pipeline was compromised
- Any source code has been exploited in the wild
- Customer-facing products or security tools were tampered with
That’s the good news. The bad news is what Trellix isn’t saying.
The company declined to disclose what specific source code was accessed, who might be behind the intrusion, or how long the attackers had access to its systems before detection. The full scope remains unknown while the investigation is ongoing.
Source code breaches against security vendors carry outsized risk. Attackers who understand how a security product works internally can craft better evasion techniques. They can identify vulnerabilities in detection logic. They can spot weaknesses in update mechanisms. Even read-only access to source code gives adversaries a significant advantage.
This incident follows a familiar pattern of security companies becoming targets themselves. Microsoft, Okta, and LastPass all suffered similar source code breaches in recent years. The irony writes itself, but the real concern is downstream. Trellix sells endpoint security and XDR products to thousands of enterprise customers worldwide.
Trellix, owned by Symphony Technology Group, has pledged to share additional technical details with the security community once its investigation concludes. Whether that transparency arrives before any exploited code becomes a problem is another matter entirely.
The Substack security roundup from Saturday morning aggregated the incident alongside the cPanel ransomware rampage and new Linux zero-days, suggesting the breach was disclosed late Friday or early Saturday.
Organizations running Trellix products should monitor the company’s advisory page for updates and consider whether additional detection rules or compensating controls are warranted until the full scope is clear.