Legit Security A.I CyberSecurity Scoring
Legit Security
Company Information
Website:http://www.legitsecurity.com
Employees number:82
Number of followers:14,599
NAICS:541514
Industry Type:Computer and Network Security
Homepage:legitsecurity.com
Legit Security Risk Score (AI oriented)
Between 750 and 799
Legit SecurityComputer and Network Security
Updated:
26/03/2026
26/03/2026
750/1000
Fair
Baa
Legit Security Global Score (TPRM)
xxxx
Legit SecurityComputer and Network Security
Score locked

Legit SecurityFair
Current Score
750Baa (FAIR)
01000
1 incidents
-17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
735
MAY 2026
734
APRIL 2026
734
MARCH 2026
750
Cyber Attack
17 Mar 2026 • Legit Security
Trivy: Trivy supply chain breach compromises over 1,000 SaaS environments, Lapsus$ joins the extortion wave
Supply Chain Attack on Trivy Expands into Lapsus$-Linked Extortion Campaign, Compromising Over 1,000 SaaS Environments
733
CRITICAL-17
AQU1774441468
Supply Chain Attack on Trivy Expands into Lapsus$-Linked Extortion Campaign, Compromising Over 1,000 SaaS Environments
A sophisticated supply chain attack targeting Trivy, a widely used open-source security scanner, has escalated into a large-scale extortion campaign linked to the cybercriminal group Lapsus$, compromising over 1,000 enterprise SaaS environments. The attack, first detected in late February, involved the compromise of Trivy’s VS Code extension, GitHub Action, and Docker Hub artifacts, with malicious payloads distributed through manipulated version tags and cached mirror infrastructure.
The threat actors, initially identified as the cloud-native group TeamPCP, gained persistent access to Aqua Security’s GitHub organization, defacing all 44 repositories with the message “TeamPCP Owns Aqua Security.” Mandiant’s investigation revealed that the attackers later funneled stolen access to broader criminal networks, including Lapsus$, known for aggressive extortion tactics.
The attack leveraged stolen credentials likely obtained through a third-party breach to backdoor multiple components, including LiteLLM, an AI middleware library embedded in cloud environments. Security firms Wiz and Socket confirmed that the campaign expanded across the npm ecosystem, with over 29 malicious packages distributed using compromised publish tokens. Despite takedown efforts, cached copies of the malicious Trivy artifacts continued circulating via mirror infrastructure like mirror.gcr.io.
Security experts warned that the attackers timed their escalation strategically, waiting until defenders were distracted by RSA Conference 2026 before launching follow-on attacks. Cory Michal (AppOmni) and Isaac Evans (Semgrep) emphasized that the incident highlights critical weaknesses in third-party code governance, with attackers exploiting implicit trust in supply chains and mutable version tags to scale their reach.
Aqua Security confirmed that its commercial products remain unaffected due to architectural isolation, but credential revocation and rotation efforts are ongoing. Mandiant has yet to determine the initial source of the stolen credentials, suspecting a breach at a business process outsourcer or partner organization.
As the fallout continues, the attackers have publicly signaled plans to target additional open-source projects, with security researchers warning that the 1,000+ downstream victims could expand significantly in the coming months. The incident underscores the growing threat of supply chain attacks, where a single compromise can cascade across thousands of organizations.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
750
JANUARY 2026
750
DECEMBER 2025
750
NOVEMBER 2025
750
OCTOBER 2025
750
SEPTEMBER 2025
750
AUGUST 2025
750
JULY 2025
750
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Legit Security ??
What was Legit Security's A.I Rankiteo Cyber Score in May 2026 ??
What was Legit Security's A.I Rankiteo Cyber Score in April 2026 ??
What was Legit Security's A.I Rankiteo Cyber Score in March 2026 ??
What was Legit Security's A.I Rankiteo Cyber Score in February 2026 ??
What was Legit Security's A.I Rankiteo Cyber Score in January 2026 ??
What was Legit Security's A.I Rankiteo Cyber Score in December 2025 ??
What was Legit Security's A.I Rankiteo Cyber Score in November 2025 ??
What was Legit Security's A.I Rankiteo Cyber Score in October 2025 ??
What was Legit Security's A.I Rankiteo Cyber Score in September 2025 ??
What was Legit Security's A.I Rankiteo Cyber Score in August 2025 ??
What was Legit Security's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on Legit Security's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Legit Security ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Legit Security's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?