Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
SecurityWeek

SecurityWeek Vendor Cyber Rating & Cyber Score

securityweek.com

SecurityWeek is at the forefront of cybersecurity news and stands as a pivotal and highly influential publication with a mission to help cybersecurity professionals defend their organizations against increasingly sophisticated cyber threats. Crafted by a seasoned editorial team and industry experts, SecurityWeek delivers informative and actionable content to help cybersecurity stakeholders from the trenches to the board room. SecurityWeek is more than a publication; it’s a resource, a guide, and a community for those at the heart of cybersecurity.


SecurityWeek A.I CyberSecurity Scoring

SecurityWeek
Company Information
Website:https://www.securityweek.com/
Employees number:10
Number of followers:7,276
NAICS:541514
Industry Type:Computer and Network Security
Homepage:securityweek.com
SecurityWeek Risk Score (AI oriented)
Between 700 and 749
logo
SecurityWeekComputer and Network Security
Updated:
30/04/2026
731/1000
Moderate
Ba
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
SecurityWeek Global Score (TPRM)
xxxx
logo
SecurityWeekComputer and Network Security
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

SecurityWeek
SecurityWeekModerate
Current Score
731Ba (MODERATE)
01000
1 incidents
-17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
732Before Incident
MAY 2026
732Before Incident
APRIL 2026
748Before Incident
Cyber Attack
01 Apr 2026SecurityWeek
Checkmarx, Trivy and SAP: Official SAP npm packages compromised to steal credentials

SAP npm Packages Compromised in Suspected TeamPCP Supply-Chain Attack

731After Incident
CRITICAL-17
CHESAPSEC1777508710
SAP npm Packages Compromised in Suspected TeamPCP Supply-Chain Attack Security researchers have uncovered a supply-chain attack targeting multiple official SAP npm packages, believed to be orchestrated by the TeamPCP threat group. The compromise affected four packages @cap-js/sqlite (v2.2.2), @cap-js/postgres (v2.2.2), @cap-js/db-service (v2.10.1), and mbt (v1.2.48) which support SAP’s Cloud Application Programming Model (CAP) and Cloud MTA, widely used in enterprise development. The malicious packages contained a preinstall script that executed automatically upon installation, deploying a loader (setup.mjs) to fetch the Bun JavaScript runtime from GitHub. This runtime then ran an obfuscated execution.js payload, designed to steal sensitive credentials from developer systems and CI/CD environments, including: - npm and GitHub authentication tokens - SSH keys and developer credentials - Cloud credentials (AWS, Azure, Google Cloud) - Kubernetes configurations and secrets - CI/CD pipeline secrets and environment variables On CI runners, the malware used an embedded Python script to scan process memory (/proc/\<pid\>/maps and /proc/\<pid\>/mem) for secrets, bypassing log masking a tactic identical to previous TeamPCP attacks, such as those targeting Bitwarden and Checkmarx. Stolen data was encrypted and exfiltrated to public GitHub repositories under victims’ accounts, marked with the description "A Mini Shai-Hulud has Appeared" a reference mirroring the "Shai-Hulud: The Third Coming" string from earlier attacks. The malware also employed GitHub commit searches as a dead-drop mechanism, decoding commit messages containing base64-encoded tokens to escalate access. Additionally, the payload included self-propagation capabilities, using stolen credentials to modify other accessible packages and repositories, further spreading the infection. Researchers have linked the attack to TeamPCP with medium confidence, citing similarities in code and tactics to prior incidents involving Trivy, Checkmarx, and Bitwarden. While the exact compromise vector remains unclear, evidence suggests an exposed NPM token from a misconfigured CircleCI job may have been exploited. SAP has not yet responded to inquiries regarding the breach. The affected package versions have since been deprecated on npm.
INCIDENT DETAILS -
TYPE
Supply-Chain Attack
MOTIVATION
Credential theft, data exfiltration, and further propagation
IMPACT
npm and GitHub authentication tokensSSH keys and developer credentialsCloud credentials (AWS, Azure, Google Cloud)Kubernetes configurations and secretsCI/CD pipeline secrets and environment variablesSystems Affected: Developer systems and CI/CD environmentsOperational Impact: Potential unauthorized access to cloud environments and CI/CD pipelinesBrand Reputation Impact: Potential reputational damage to SAP due to compromised official packagesIdentity Theft Risk: High (stolen developer and cloud credentials)
DATA BREACH
Authentication tokensSSH keysCloud credentialsKubernetes secretsCI/CD pipeline secretsSensitivity Of Data: HighData Exfiltration: Yes (to public GitHub repositories under victims’ accounts)Data Encryption: Yes (stolen data was encrypted before exfiltration)
MARCH 2026
748Before Incident
FEBRUARY 2026
748Before Incident
JANUARY 2026
748Before Incident
DECEMBER 2025
748Before Incident
NOVEMBER 2025
748Before Incident
OCTOBER 2025
748Before Incident
SEPTEMBER 2025
748Before Incident
AUGUST 2025
748Before Incident
JULY 2025
748Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for SecurityWeek ?
?
What was SecurityWeek's A.I Rankiteo Cyber Score in May 2026 ?
?
What was SecurityWeek's A.I Rankiteo Cyber Score in April 2026 ?
?
What was SecurityWeek's A.I Rankiteo Cyber Score in March 2026 ?
?
What was SecurityWeek's A.I Rankiteo Cyber Score in February 2026 ?
?
What was SecurityWeek's A.I Rankiteo Cyber Score in January 2026 ?
?
What was SecurityWeek's A.I Rankiteo Cyber Score in December 2025 ?
?
What was SecurityWeek's A.I Rankiteo Cyber Score in November 2025 ?
?
What was SecurityWeek's A.I Rankiteo Cyber Score in October 2025 ?
?
What was SecurityWeek's A.I Rankiteo Cyber Score in September 2025 ?
?
What was SecurityWeek's A.I Rankiteo Cyber Score in August 2025 ?
?
What was SecurityWeek's A.I Rankiteo Cyber Score in July 2025 ?
?
What is the average per-incident point impact on SecurityWeek's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with SecurityWeek ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view SecurityWeek's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
SecurityWeek Cyber Scoring History | Rankiteo