Security vendors occupy a position almost nothing else does. Their software runs with high privilege on endpoints across their customer base, it is trusted to update itself, and it is specifically exempted from the controls that would flag its behaviour elsewhere.
In May 2026 the RansomHouse group claimed access to source code repositories at Trellix, a vendor whose products protect a very large installed base. The claim was made publicly; we have not seen it corroborated, and we grade this file low accordingly.
What Source Code Access Would And Would Not Mean
It is worth being precise, because this is a category where vague reporting does real harm. Source code is not a signing key and it is not build infrastructure. Reading code does not let anyone push an update to customers.
What it can offer is a map: which checks exist, how detection logic is structured, where the assumptions are. That is useful to someone building evasion, and it is durable, because detection architecture changes far more slowly than signatures do.
The reason to hold vendors to a visible standard is not schadenfreude. It is that their customers made a security decision on the strength of the vendor’s own claims, and have no independent way to check whether those claims still hold.
We asked the obvious questions and will update the file if they are answered. Until then this remains a claim, and it is graded as one.
Compiled from public reporting, listed below. The claim originates with the group; we have not verified it and have not reviewed any listed material. Corrections: corrections@forensicpost.com.
- List of recent data breaches in 2026Bright Defense