
A significant security breach has affected Aqua Security's Trivy vulnerability scanner, impacting nearly all versions in a supply chain attack that poses serious risks for developers and their organizations. The incident was confirmed by Itay Shakury, a maintainer of Trivy, following a series of discussions on the matter that were later deleted by the attackers. The attack unfolded in the early hours of Thursday, during which hackers exploited stolen credentials to execute a forced push. This action resulted in the alteration of nearly all trivy-action tags and seven setup-trivy tags, replacing them with malicious dependencies. A forced push circumvents the standard safeguards in Git, allowing for the overwriting of existing commits, which creates an avenue for potential exploitation. Trivy is instrumental for developers, being utilized to identify vulnerabilities and detect hardcoded authentication secrets throughout software development pipelines. With over 33,200 stars on GitHub, its popularity underscores its critical role in modern software development. In a warning to users, Shakury advised that if there’s a chance of using a compromised version, all pipeline secrets should be considered at risk and should be rotated immediately. Security firms Socket and Wiz reported that the malware linked to 75 compromised trivy-action tags is designed to thoroughly search development environments for sensitive information such as GitHub tokens, cloud credentials, SSH keys, and Kubernetes tokens. Once these secrets are detected, the malware encrypts the data before sending it to servers controlled by the attackers. Consequently, any CI/CD pipeline that utilizes software referencing the compromised version tags will execute malicious code when a Trivy scan is performed. The spoofed version tags notably include widely used releases like @0.34.2, @0.33, and @0.18.0, with only version @0.35.0 remaining unaffected.
As technology continues to evolve, a notable shift is occurring in the relationship between humans and artificial intell...
Business Insider | Jul 25, 2026, 09:50In a dramatic turn of events within the AI landscape, Hugging Face faced a significant security breach involving an AI a...
Business Insider | Jul 25, 2026, 20:30In recent discussions, a once-obscure topic in artificial intelligence has surged to the forefront of debates among tech...
CNBC | Jul 25, 2026, 12:15
Kalshi, the prediction market platform, has taken significant legal steps against Netflix, sending a cease-and-desist le...
TechCrunch | Jul 25, 2026, 17:10
Monday.com, the innovative work management platform based in Tel Aviv, has recently announced significant layoffs, attri...
TechCrunch | Jul 26, 2026, 01:45