Robuta

https://arstechnica.com/security/2026/03/widely-used-trivy-scanner-compromised-in-ongoing-supply-chain-attack/ Widely used Trivy scanner compromised in ongoing supply-chain attack - Ars Technica Mar 20, 2026 - Admins: Sorry to say, but it's likely a rotate-your-secrets kind of weekend. supply chain attackwidely usedars technicatrivyscanner https://trivy.dev/ Trivy trivy Sponsored https://www.xotic.ai/explore Explore AI Girlfriend & AI Characters | Xotic Find your perfect AI girlfriend or explore thousands of unique AI characters. Filter by anime or realistic styles, gender preferences, and discover immersive... https://www.stepsecurity.io/blog/trivy-compromised-a-second-time---malicious-v0-69-4-release Trivy Compromised a Second Time - Malicious v0.69.4 Release, aquasecurity/setup-trivy,... On March 19, 2026, trivy — a widely used open source vulnerability scanner maintained by Aqua Security — experienced a second security incident. Three weeks... second time69 4trivycompromisedv0 https://trivy.dev/partners Partners - Trivy Jan 2, 2023 - Partner with the world’s most trusted open-source security scanner through this premium program, which gives you priority support, co‑branding rights, and... partnerstrivy https://infra.apache.org/blog/trivy_security_incident.html Trivy Security Incident - Apache Infrastructure Website security incidenttrivyapacheinfrastructurewebsite https://hackaday.com/tag/trivy/ Trivy | Hackaday trivyhackaday https://www.csoonline.com/article/4148317/trivy-vulnerability-scanner-backdoored-with-credential-stealer-in-supply-chain-attack.html Trivy vulnerability scanner backdoored with credential stealer in supply chain attack | CSO Online Mar 21, 2026 - ‘If you suspect you were running a compromised version, treat all pipeline secrets as compromised and rotate immediately,’ Trivy maintainer says. supply chain attackvulnerability scannercso onlinetrivycredential Sponsored https://www.cheekycrush.com/ CheekyCrush https://trivy.dev/docs/latest/guide/compliance/compliance/ Built-in Compliance - Trivy Trivy - All-in-one open source security scanner built incompliancetrivy https://www.csoonline.com/article/4149938/trivy-supply-chain-breach-compromises-over-1000-saas-environments-lapsus-joins-the-extortion-wave.html Trivy supply chain breach compromises over 1,000 SaaS environments, Lapsus$ joins the extortion... Mar 25, 2026 - Socket and Wiz confirm widespread credential theft and worm‑like propagation, with cached malicious Trivy artifacts still circulating across mirror... supply chain1 000trivybreachsaas https://hub.docker.com/hardened-images/catalog/dhi/trivy-operator Hardened Images catalog | Trivy Operator | Docker Hub hardened imagesdocker hubcatalogtrivyoperator https://trivy.dev/docs/latest/guide/ Overview - Trivy Trivy - All-in-one open source security scanner overviewtrivy https://www.aikido.dev/blog/teampcp-deploys-worm-npm-trivy-compromise TeamPCP deploys CanisterWorm on NPM following Trivy compromise Mar 21, 2026 - TeamPCP deploys CanisterWorm on NPM following Trivy compromise npmfollowingtrivycompromise https://training.linuxfoundation.org/resources/scanning-container-images-using-trivy/ Scanning Container Images Using Trivy - Linux Foundation - Education Nov 20, 2025 - Scanning Container Images Using Trivy container imageslinux foundationscanningusingtrivy https://gitlab.com/gitlab-org/security-products/analyzers/trivy-k8s-wrapper GitLab.org / security-products / analyzers / Trivy K8S wrapper · GitLab A wrapper image for running Trivy K8S in gitlab-agent. This image is used for Operational Container Scanning. security productsgitlabanalyzerstrivyk8s https://www.csoonline.com/article/4154176/cert-eu-blames-trivy-supply-chain-attack-for-europa-eu-data-breach.html CERT-EU blames Trivy supply chain attack for Europa.eu data breach | CSO Online Apr 3, 2026 - Attackers exploited a vulnerability scanner to steal 350GB of data that they then leaked on the dark web. supply chain attackdata breachcso onlinecerteu https://www.networkworld.com/article/4154185/cert-eu-blames-trivy-supply-chain-attack-for-europa-eu-data-breach-2.html CERT-EU blames Trivy supply chain attack for Europa.eu data breach | Network World Apr 3, 2026 - Attackers exploited a vulnerability scanner to steal 350GB of data that they then leaked on the dark web. supply chain attackdata breachnetwork worldcerteu https://www.infoworld.com/article/4154187/cert-eu-blames-trivy-supply-chain-attack-for-europa-eu-data-breach-3.html CERT-EU blames Trivy supply chain attack for Europa.eu data breach | InfoWorld Apr 3, 2026 - Attackers exploited a vulnerability scanner to steal 350GB of data that they then leaked on the dark web. supply chain attackdata breachcerteutrivy https://www.theregister.com/2026/03/24/1k_cloud_environments_infected_following/ 1K+ cloud environments infected via Trivy attack • The Register Apr 1, 2026 - RSAC 2026: Crims 'creating a snowball effect' across open source projects the register1kcloudenvironmentsinfected https://www.docker.com/blog/trivy-kics-and-the-shape-of-supply-chain-attacks-so-far-in-2026/ Trivy, KICS, and the shape of supply chain attacks so far in 2026 | Docker Apr 23, 2026 - We caught a malicious image pushed to checkmarx/kics on Docker Hub, the image was quarantined, and we coordinated response with Socket and Checkmarx. This blog... supply chain attackstrivyshapefardocker https://trivy.dev/docs/latest/guide/references/configuration/cli/trivy_registry_logout/ Registry Logout - Trivy Trivy - All-in-one open source security scanner registrylogouttrivy