Close Menu
Savannah HeraldSavannah Herald
  • Home
  • News
    • Local
    • State
    • National
    • World
    • HBCUs
  • Events
  • Directories
  • Weather
  • Traffic
  • Sports
  • Politics
  • Lifestyle
    • Faith
    • Senior Living
    • Health
    • Travel
    • Beauty
    • Fashion
    • Food
    • Art & Literature
  • Business
    • Real Estate
    • Entertainment
    • Investing
    • Education
  • Guides
    • Juneteenth Guide
    • Black History Savannah
    • MLK Guide Savannah
We're Social
  • Twitter
  • Facebook
  • YouTube

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

Trending
  • Why Do Health Disparities Exist If Race Is a Social Construct?
  • Ramp in talks to hit $40B+ valuation, 6 months after reaching $32B
  • Georgia Trend Daily – May 7, 2026
  • Arthur Blank’s role in opening U.S. Soccer Training Center
  • Fundraiser Cruises with Carnival, Royal Caribbean Cruises & More
  • TODAY’S MASS EXPLAINER | Catholics worldwide reflect on faith, service, and seeing God in Jesus at today’s mass
  • Jury finds city of LA not liable in death of 14-year-old girl hit by police officer’s stray bullet
  • Ghana Is The Latest To Reflect Health Funding Agreement
Facebook X (Twitter) Instagram YouTube
Login
Savannah HeraldSavannah Herald
  • Home
  • News
    • Local
    • State
    • National
    • World
    • HBCUs
  • Events
  • Directories
  • Weather
  • Traffic
  • Sports
  • Politics
  • Lifestyle
    • Faith
    • Senior Living
    • Health
    • Travel
    • Beauty
    • Fashion
    • Food
    • Art & Literature
  • Business
    • Real Estate
    • Entertainment
    • Investing
    • Education
  • Guides
    • Juneteenth Guide
    • Black History Savannah
    • MLK Guide Savannah
Savannah HeraldSavannah Herald
Home » Widely used Trivy scanner compromised in ongoing supply-chain attack
Tech

Widely used Trivy scanner compromised in ongoing supply-chain attack

Savannah HeraldBy Savannah HeraldMarch 22, 20262 Mins Read
Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
A stylized skull and crossbones made out of ones and zeroes.
Share
Facebook Twitter LinkedIn Pinterest Email

Tech Trends & Innovation: The Latest in Tech News

Key takeaways
  • Trivy maintainer Itay Shakury confirmed the compromise; attackers used stolen credentials to force-push many trivy-action and setup-trivy tags to malicious dependencies.
  • If you ran a compromised version, treat all pipeline secrets as compromised and rotate immediately, Itay Shakury advised.
  • Socket and Wiz say malware in 75 compromised trivy-action tags steals GitHub tokens, cloud credentials, SSH and Kubernetes keys, then exfiltrates them.

Hackers have compromised virtually all versions of Aqua Security’s widely used Trivy vulnerability scanner in an ongoing supply chain attack that could have wide-ranging consequences for developers and the organizations that use them.

Trivy maintainer Itay Shakury confirmed the compromise on Friday, following rumors and a thread, since deleted by the attackers, discussing the incident. The attack began in the early hours of Thursday. When it was done, the threat actor had used stolen credentials to force-push all but one of the trivy-action tags and seven setup-trivy tags to use malicious dependencies.

Assume your pipelines are compromised

A forced push is a git command that overrides a default safety mechanism that protects against overwriting existing commits. Trivy is a vulnerability scanner that developers use to detect vulnerabilities and inadvertently hardcoded authentication secrets in pipelines for developing and deploying software updates. The scanner has 33,200 stars on GitHub, a high rating that indicates it’s used widely.

“If you suspect you were running a compromised version, treat all pipeline secrets as compromised and rotate immediately,” Shakury wrote.

Security firms Socket and Wiz said that the malware, triggered in 75 compromised trivy-action tags, causes custom malware to thoroughly scour development pipelines, including developer machines, for GitHub tokens, cloud credentials, SSH keys, Kubernetes tokens, and whatever other secrets may live there. Once found, the malware encrypts the data and sends it to an attacker-controlled server.

The end result, Socket said, is that any CI/CD pipeline using software that references compromised version tags executes code as soon as the Trivy scan is run. Spoofed version tags include the widely used @0.34.2, @0.33, and @0.18.0. Version @0.35.0 appears to be the only one unaffected.

Read the full article from the original source


AI and Machine Learning artificial intelligence Consumer Electronics Cybersecurity Updates Data Privacy Digital Trends Enterprise Technology Future of Work Gadget Reviews Green Tech Mobile Tech Robotics News Science and Technology Silicon Valley News Software Development Startups and Tech Tech Industry Insights Tech Innovation Tech Policy Technology News
Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
Savannah Herald
  • Website

Related Posts

Tech May 7, 2026

Ramp in talks to hit $40B+ valuation, 6 months after reaching $32B

Tech May 7, 2026

Market research is too slow for the AI era, so Brox built 60,000 identical ‘digital twins’ of real people you can survey instantly, repeatedly

Tech May 7, 2026

TSMC taps wind power as AI chip demand soars, Taiwan feels energy crunch

Tech May 5, 2026

‘I Actually Thought He Was Going to Hit Me,’ OpenAI’s Greg Brockman Says of Elon Musk

Tech May 5, 2026

MUSIC MONDAY: “A Love Supreme: The Essential John Coltrane Playlist” (LISTEN) – Good Black News

Tech May 4, 2026

Surfshark Adds Vega OS Support, Expanding VPN Access on Amazon Fire TV

Comments are closed.

Don't Miss
Faith August 28, 2025By Savannah Herald06 Mins Read

Dear Pope Leo, here’s how Madonna’s idea about going to Gaza might work

August 28, 2025

Faith & Reflection: Voices from the Black Church and Beyond (RNS) — Your Holiness, Pope…

Exactly how Gen X can get ready for their moms and dads care demands currently

August 28, 2025

On Educator Admiration Week, Union Leaders State Educators are Underpaid and Under Fire

April 16, 2026

City to Host Super Saturday Grant Kickoff Event

February 2, 2026

How to Plan Your First Trip to a Formula One Race, According to a Travel Advisor

September 3, 2025
Archives
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
Categories
  • Art & Literature
  • Beauty
  • Black History
  • Business
  • Climate
  • Education
  • Employment
  • Entertainment
  • Faith
  • Fashion
  • Food
  • Gaming
  • Georgia Politics
  • HBCUs
  • Health
  • Health Inspections
  • Investing
  • Lifestyle
  • Local
  • Lowcountry News
  • National
  • National Opinion
  • News
  • Politics
  • Real Estate
  • Senior Living
  • Sports
  • State
  • Tech
  • Transportation
  • Travel
  • World
Savannah Herald Newsletter

Subscribe to Updates

A round up interesting pic’s, post and articles in the C-Port and around the world.

About Us
About Us

The Savannah Herald is your trusted source for the pulse of Coastal Georgia and the Low County of South Carolina. We're committed to delivering timely news that resonates with the African American community.

From local politics to business developments, we're here to keep you informed and engaged. Our mission is to amplify the voices and stories that matter, shining a light on our collective experiences and achievements.
We cover:
🏛️ Politics
💼 Business
🎭 Entertainment
🏀 Sports
🩺 Health
💻 Technology
Savannah Herald: Savannah's Black Voice 💪🏾

Our Picks

Two arrested following gunfire in Academy Springs Park on Sunday

February 28, 2026

Chatham County Board of Commissioners Notice – Savannah Herald

December 17, 2025

Dry Bar Concepts|Redfin

November 25, 2025

Out of the Rough: Ted Rhodes and His Fight Against Golf’s Color Barrier  – African American Golfer’s Digest

April 28, 2026

Sheet Pan Pizza for a Crowd

March 19, 2026
Categories
  • Art & Literature
  • Beauty
  • Black History
  • Business
  • Climate
  • Education
  • Employment
  • Entertainment
  • Faith
  • Fashion
  • Food
  • Gaming
  • Georgia Politics
  • HBCUs
  • Health
  • Health Inspections
  • Investing
  • Lifestyle
  • Local
  • Lowcountry News
  • National
  • National Opinion
  • News
  • Politics
  • Real Estate
  • Senior Living
  • Sports
  • State
  • Tech
  • Transportation
  • Travel
  • World
  • Privacy Policies
  • Disclaimers
  • Terms and Conditions
  • About Us
  • Contact Us
  • Opt-Out Preferences
  • Accessibility Statement
Copyright © 2002-2026 Savannahherald.com All Rights Reserved. A Veteran-Owned Business

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login below or Register Now.

Lost password?

Register Now!

Already registered? Login.

A password will be e-mailed to you.