Trivy Supply Chain Breach Hijacks GitHub Actions to Steal CI/CD Secrets
Trivy, a widely used open‑source vulnerability scanner maintained by Aqua Security, was compromised again in March 2026 when attackers hijacked 75 version tags of its associated GitHub Actions workflows to distribute malicious code that steals sensitive CI/CD secrets from developer environments. The breach involved force‑pushing malicious commits into trusted action tags, exposing SSH keys, cloud credentials, and other secrets to attackers. This second supply‑chain incident underscores risks in CI/CD tooling and the need for stricter workflow security practices.
https://thehackernews.com/2026/03/trivy-security-scanner-github-actions.html
Comments
Post a Comment