Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Legit Security

Legit Security Vendor Cyber Rating & Cyber Score

legitsecurity.com

Legit Security is the AppSec platform purpose-built to secure AI-powered development. Legit VibeGuard provides complete visibility and security for AI code and development processes. Legit ASPM extends that protection across your entire SDLC – unifying AppSec testing, secrets prevention, software supply chain security and vulnerability management in a unified control plane.


Legit Security A.I CyberSecurity Scoring

Legit Security
Company Information
Website:http://www.legitsecurity.com
Employees number:82
Number of followers:14,599
NAICS:541514
Industry Type:Computer and Network Security
Homepage:legitsecurity.com
Legit Security Risk Score (AI oriented)
Between 750 and 799
logo
Legit SecurityComputer and Network Security
Updated:
26/03/2026
750/1000
Fair
Baa
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Legit Security Global Score (TPRM)
xxxx
logo
Legit SecurityComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

Legit Security
Legit SecurityFair
Current Score
750Baa (FAIR)
01000
1 incidents
-17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
735Before Incident
MAY 2026
734Before Incident
APRIL 2026
734Before Incident
MARCH 2026
750Before Incident
Cyber Attack
17 Mar 2026Legit Security
Trivy: Trivy supply chain breach compromises over 1,000 SaaS environments, Lapsus$ joins the extortion wave

Supply Chain Attack on Trivy Expands into Lapsus$-Linked Extortion Campaign, Compromising Over 1,000 SaaS Environments

733After Incident
CRITICAL-17
AQU1774441468
Supply Chain Attack on Trivy Expands into Lapsus$-Linked Extortion Campaign, Compromising Over 1,000 SaaS Environments A sophisticated supply chain attack targeting Trivy, a widely used open-source security scanner, has escalated into a large-scale extortion campaign linked to the cybercriminal group Lapsus$, compromising over 1,000 enterprise SaaS environments. The attack, first detected in late February, involved the compromise of Trivy’s VS Code extension, GitHub Action, and Docker Hub artifacts, with malicious payloads distributed through manipulated version tags and cached mirror infrastructure. The threat actors, initially identified as the cloud-native group TeamPCP, gained persistent access to Aqua Security’s GitHub organization, defacing all 44 repositories with the message “TeamPCP Owns Aqua Security.” Mandiant’s investigation revealed that the attackers later funneled stolen access to broader criminal networks, including Lapsus$, known for aggressive extortion tactics. The attack leveraged stolen credentials likely obtained through a third-party breach to backdoor multiple components, including LiteLLM, an AI middleware library embedded in cloud environments. Security firms Wiz and Socket confirmed that the campaign expanded across the npm ecosystem, with over 29 malicious packages distributed using compromised publish tokens. Despite takedown efforts, cached copies of the malicious Trivy artifacts continued circulating via mirror infrastructure like mirror.gcr.io. Security experts warned that the attackers timed their escalation strategically, waiting until defenders were distracted by RSA Conference 2026 before launching follow-on attacks. Cory Michal (AppOmni) and Isaac Evans (Semgrep) emphasized that the incident highlights critical weaknesses in third-party code governance, with attackers exploiting implicit trust in supply chains and mutable version tags to scale their reach. Aqua Security confirmed that its commercial products remain unaffected due to architectural isolation, but credential revocation and rotation efforts are ongoing. Mandiant has yet to determine the initial source of the stolen credentials, suspecting a breach at a business process outsourcer or partner organization. As the fallout continues, the attackers have publicly signaled plans to target additional open-source projects, with security researchers warning that the 1,000+ downstream victims could expand significantly in the coming months. The incident underscores the growing threat of supply chain attacks, where a single compromise can cascade across thousands of organizations.
INCIDENT DETAILS -
TYPE
Supply Chain Attack, Extortion Campaign
MOTIVATION
ExtortionData theftSupply chain disruption
IMPACT
1,000+ enterprise SaaS environmentsGitHub repositoriesnpm ecosystemOperational Impact: Credential revocation and rotation efforts ongoingBrand Reputation Impact: Defacement of Aqua Security’s GitHub repositories
DATA BREACH
Stolen credentialsAccess tokensSensitivity Of Data: High (potential access to enterprise SaaS environments)
FEBRUARY 2026
750Before Incident
JANUARY 2026
750Before Incident
DECEMBER 2025
750Before Incident
NOVEMBER 2025
750Before Incident
OCTOBER 2025
750Before Incident
SEPTEMBER 2025
750Before Incident
AUGUST 2025
750Before Incident
JULY 2025
750Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Legit Security ?
?
What was Legit Security's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Legit Security's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Legit Security's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Legit Security's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Legit Security's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Legit Security's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Legit Security's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Legit Security's A.I Rankiteo Cyber Score in October 2025 ?
?
What was Legit Security's A.I Rankiteo Cyber Score in September 2025 ?
?
What was Legit Security's A.I Rankiteo Cyber Score in August 2025 ?
?
What was Legit Security's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on Legit Security's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Legit Security ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Legit Security's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?