Close Menu
Savannah HeraldSavannah Herald
  • Home
  • News
    • Local
    • State
    • National
    • World
    • HBCUs
  • Events
  • Weather
  • Traffic
  • Obituaries
  • Sports
  • Politics
  • Lifestyle
    • Faith
    • Beauty
    • Fashion
    • Food
    • Art & Literature
    • Travel
    • Senior Living
    • Black History
  • Health
  • Business
    • Investing
    • Gaming
    • Education
    • Entertainment
    • Tech
    • Real Estate
  • More
    • Health Inspections
    • A List of Our Online Black Newspapers in America
  • Guides
    • Black History Savannah
    • MLK Guide Savannah
We're Social
  • Twitter
  • Facebook
  • YouTube

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

Trending
  • Weight-loss drugs do work – but not on their own | Weight-loss drugs
  • Dinos tu personalidad y te diremos tu deporte invernal
  • Widely used Trivy scanner compromised in ongoing supply-chain attack
  • RPS Verdict: Anime racer Screamer slides sideways into success with its colourful, characterful driving
  • Sweet Potato Brownies – Make It Dairy Free
  • Stop underdressing your eggs – Salon.com
  • Explore the Latest Spider Hoodie Collection
  • James Cleverly says he disagrees with Nick Timothy about Islamic public prayer | James Cleverly
Facebook X (Twitter) Instagram YouTube
Login
Savannah HeraldSavannah Herald
  • Home
  • News
    • Local
    • State
    • National
    • World
    • HBCUs
  • Events
  • Weather
  • Traffic
  • Obituaries
  • Sports
  • Politics
  • Lifestyle
    • Faith
    • Beauty
    • Fashion
    • Food
    • Art & Literature
    • Travel
    • Senior Living
    • Black History
  • Health
  • Business
    • Investing
    • Gaming
    • Education
    • Entertainment
    • Tech
    • Real Estate
  • More
    • Health Inspections
    • A List of Our Online Black Newspapers in America
  • Guides
    • Black History Savannah
    • MLK Guide Savannah
Savannah HeraldSavannah Herald
Home » Widely used Trivy scanner compromised in ongoing supply-chain attack
Tech

Widely used Trivy scanner compromised in ongoing supply-chain attack

Savannah HeraldBy Savannah HeraldMarch 22, 20262 Mins Read
Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
A stylized skull and crossbones made out of ones and zeroes.
Share
Facebook Twitter LinkedIn Pinterest Email

Tech Trends & Innovation: The Latest in Tech News

Key takeaways
  • Trivy maintainer Itay Shakury confirmed the compromise; attackers used stolen credentials to force-push many trivy-action and setup-trivy tags to malicious dependencies.
  • If you ran a compromised version, treat all pipeline secrets as compromised and rotate immediately, Itay Shakury advised.
  • Socket and Wiz say malware in 75 compromised trivy-action tags steals GitHub tokens, cloud credentials, SSH and Kubernetes keys, then exfiltrates them.

Hackers have compromised virtually all versions of Aqua Security’s widely used Trivy vulnerability scanner in an ongoing supply chain attack that could have wide-ranging consequences for developers and the organizations that use them.

Trivy maintainer Itay Shakury confirmed the compromise on Friday, following rumors and a thread, since deleted by the attackers, discussing the incident. The attack began in the early hours of Thursday. When it was done, the threat actor had used stolen credentials to force-push all but one of the trivy-action tags and seven setup-trivy tags to use malicious dependencies.

Assume your pipelines are compromised

A forced push is a git command that overrides a default safety mechanism that protects against overwriting existing commits. Trivy is a vulnerability scanner that developers use to detect vulnerabilities and inadvertently hardcoded authentication secrets in pipelines for developing and deploying software updates. The scanner has 33,200 stars on GitHub, a high rating that indicates it’s used widely.

“If you suspect you were running a compromised version, treat all pipeline secrets as compromised and rotate immediately,” Shakury wrote.

Security firms Socket and Wiz said that the malware, triggered in 75 compromised trivy-action tags, causes custom malware to thoroughly scour development pipelines, including developer machines, for GitHub tokens, cloud credentials, SSH keys, Kubernetes tokens, and whatever other secrets may live there. Once found, the malware encrypts the data and sends it to an attacker-controlled server.

The end result, Socket said, is that any CI/CD pipeline using software that references compromised version tags executes code as soon as the Trivy scan is run. Spoofed version tags include the widely used @0.34.2, @0.33, and @0.18.0. Version @0.35.0 appears to be the only one unaffected.

Read the full article from the original source


AI and Machine Learning artificial intelligence Consumer Electronics Cybersecurity Updates Data Privacy Digital Trends Enterprise Technology Future of Work Gadget Reviews Green Tech Mobile Tech Robotics News Science and Technology Silicon Valley News Software Development Startups and Tech Tech Industry Insights Tech Innovation Tech Policy Technology News
Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
Savannah Herald
  • Website

Related Posts

Tech March 21, 2026

Today’s NYT Mini Crossword Answers for March 21

Tech March 20, 2026

AI-powered hospital cyberattacks increasingly target healthcare workers

Tech March 19, 2026

FCC Enforcement Chief Offered to Help Brendan Carr Target Disney, Records Show

Tech March 19, 2026

The Download: Quantum computing for health, and why the world doesn’t recycle more nuclear waste

Tech March 18, 2026

Best Amazon Big Spring Sale Apple Watch deals 2026: Save on Series 11 and SE 3 models

Tech March 17, 2026

UK Man Accuses Spouse of Stealing $172 Million Bitcoin Password via CCTV Camera

Comments are closed.

Don't Miss
Business December 2, 2025By Savannah Herald03 Mins Read

Jamal Bryant-Led Atlanta Church Hosts Black Businesses Market

December 2, 2025

Empowering Black Entrepreneurship: Stories of Success, Strategy & Growth by Nahlah Abdur-Rahman November 30, 2025…

Pooler Area Event | Santa Claus Is Coming to Town

November 26, 2025

National Black Beauty Week Is Here To Change The Way We See, Celebrate And Experience Black Beauty

November 16, 2025

Victoria Reese Brathwaite Is Reshaping Ideas About Chronic Illnesses

December 15, 2025

Kwanzaa Begins – Castle Senior Living at Forest Hills

December 28, 2025
Archives
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • December 2024
Categories
  • Art & Literature
  • Beauty
  • Black History
  • Business
  • Climate
  • Education
  • Employment
  • Entertainment
  • Faith
  • Fashion
  • Food
  • Gaming
  • HBCUs
  • Health
  • Health Inspections
  • Home & Garden
  • Investing
  • Local
  • Lowcountry News
  • National
  • News
  • Obituaries
  • Politics
  • Real Estate
  • Science
  • Senior Living
  • Sports
  • SSU Homecoming 2024
  • State
  • Tech
  • Transportation
  • Travel
  • World
Savannah Herald Newsletter

Subscribe to Updates

A round up interesting pic’s, post and articles in the C-Port and around the world.

About Us
About Us

The Savannah Herald is your trusted source for the pulse of Coastal Georgia and the Low County of South Carolina. We're committed to delivering timely news that resonates with the African American community.

From local politics to business developments, we're here to keep you informed and engaged. Our mission is to amplify the voices and stories that matter, shining a light on our collective experiences and achievements.
We cover:
🏛️ Politics
💼 Business
🎭 Entertainment
🏀 Sports
🩺 Health
💻 Technology
Savannah Herald: Savannah's Black Voice 💪🏾

Our Picks

Democrats, Let Trump and Elon Fight

August 28, 2025

Deborah Farmer Kris: How Awe Helps Us Flourish

November 25, 2025

The Black Swan Who Defied Racism to Become America’s First Black Concert Star 👀

August 28, 2025

Bad Bunny at the Super Bowl is making MAGA mad, and Black social media users are loving it

September 30, 2025

Zero Percent, No-Fee Student Loans –

February 4, 2026
Categories
  • Art & Literature
  • Beauty
  • Black History
  • Business
  • Climate
  • Education
  • Employment
  • Entertainment
  • Faith
  • Fashion
  • Food
  • Gaming
  • HBCUs
  • Health
  • Health Inspections
  • Home & Garden
  • Investing
  • Local
  • Lowcountry News
  • National
  • News
  • Obituaries
  • Politics
  • Real Estate
  • Science
  • Senior Living
  • Sports
  • SSU Homecoming 2024
  • State
  • Tech
  • Transportation
  • Travel
  • World
  • Privacy Policies
  • Disclaimers
  • Terms and Conditions
  • About Us
  • Contact Us
  • Opt-Out Preferences
  • Accessibility Statement
Copyright © 2002-2026 Savannahherald.com All Rights Reserved. A Veteran-Owned Business

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login below or Register Now.

Lost password?

Register Now!

Already registered? Login.

A password will be e-mailed to you.