Cybersecurity firm Trellix says it has experienced a breach after attackers gained unauthorized access to part of its source code repository. Trellix reports that it recently identified the compromise and began working with forensic experts to investigate and remediate it. The company also says it has notified law enforcement.
Across reports, Trellix does not provide detailed information about the scope of the intrusion, but it characterizes the accessed material as “a portion” of its source code. Multiple outlets report that Trellix has not found evidence that its source code release or distribution process was impacted, indicating that the company believes published releases were not affected.
Some coverage also notes that source code repository breaches can pose supply-chain and detection risks, though specific impacts in this case remain unclear. In addition, one outlet reports that the breach has been claimed by the “RansomHouse” threat group and that the group released a small set of images as proof of intrusion. Overall, public details about timing, affected systems, and any downstream impact remain limited as the investigation continues.