🚨 Trivy update: maintainers confirm this attack used a compromised credential carried over from the breach in early March. We’ve updated our analysis with full details on how 75 GitHub Action tags were poisoned and used to exfiltrate secrets during CI runs. socket.dev/blog/trivy-u...
Trivy Under Attack Again: Widespread GitHub Actions Tag Comp...
Attackers compromised Trivy GitHub Actions by force-updating tags to deliver malware, exposing CI/CD secrets across affected pipelines.
socket.dev