Close Menu
Savannah HeraldSavannah Herald
    We're Social
    • Twitter
    • Facebook
    • YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Trending
    • NexGen Global Green Housing announced a groundbreaking initiative for Baltimore City Section 8 residents to select a residential lot anywhere in the city
    • Atmus Filtration Technologies Names Kevin Carpenter Senior Vice President & Chief Supply Chain Officer
    • Storm Reid Joins Cast of Coming-of-Age Revenge Thriller ‘Hot Year’
    • Weather pushes back Game 2 of SCISA 4A baseball state title series
    • Kardea Brown on Love, Diabetes, and Reimagining Tradition
    • Protect your enterprise now from the Shai-Hulud worm and npm vulnerability in 6 actionable steps
    • Georgia Trend Daily – May 12, 2026
    • Jason Collins, NBA’s first openly gay player, dies at 47
    Facebook X (Twitter) Instagram YouTube
    Login
    Savannah HeraldSavannah Herald
    Savannah HeraldSavannah Herald
    Home » Widely used Trivy scanner compromised in ongoing supply-chain attack
    Tech

    Widely used Trivy scanner compromised in ongoing supply-chain attack

    Savannah HeraldBy Savannah HeraldMarch 22, 20262 Mins Read
    Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    A stylized skull and crossbones made out of ones and zeroes.
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Tech Trends & Innovation: The Latest in Tech News

    Key takeaways
    • Trivy maintainer Itay Shakury confirmed the compromise; attackers used stolen credentials to force-push many trivy-action and setup-trivy tags to malicious dependencies.
    • If you ran a compromised version, treat all pipeline secrets as compromised and rotate immediately, Itay Shakury advised.
    • Socket and Wiz say malware in 75 compromised trivy-action tags steals GitHub tokens, cloud credentials, SSH and Kubernetes keys, then exfiltrates them.

    Hackers have compromised virtually all versions of Aqua Security’s widely used Trivy vulnerability scanner in an ongoing supply chain attack that could have wide-ranging consequences for developers and the organizations that use them.

    Trivy maintainer Itay Shakury confirmed the compromise on Friday, following rumors and a thread, since deleted by the attackers, discussing the incident. The attack began in the early hours of Thursday. When it was done, the threat actor had used stolen credentials to force-push all but one of the trivy-action tags and seven setup-trivy tags to use malicious dependencies.

    Assume your pipelines are compromised

    A forced push is a git command that overrides a default safety mechanism that protects against overwriting existing commits. Trivy is a vulnerability scanner that developers use to detect vulnerabilities and inadvertently hardcoded authentication secrets in pipelines for developing and deploying software updates. The scanner has 33,200 stars on GitHub, a high rating that indicates it’s used widely.

    “If you suspect you were running a compromised version, treat all pipeline secrets as compromised and rotate immediately,” Shakury wrote.

    Security firms Socket and Wiz said that the malware, triggered in 75 compromised trivy-action tags, causes custom malware to thoroughly scour development pipelines, including developer machines, for GitHub tokens, cloud credentials, SSH keys, Kubernetes tokens, and whatever other secrets may live there. Once found, the malware encrypts the data and sends it to an attacker-controlled server.

    The end result, Socket said, is that any CI/CD pipeline using software that references compromised version tags executes code as soon as the Trivy scan is run. Spoofed version tags include the widely used @0.34.2, @0.33, and @0.18.0. Version @0.35.0 appears to be the only one unaffected.

    Read the full article from the original source


    AI and Machine Learning artificial intelligence Consumer Electronics Cybersecurity Updates Data Privacy Digital Trends Enterprise Technology Future of Work Gadget Reviews Green Tech Mobile Tech Robotics News Science and Technology Silicon Valley News Software Development Startups and Tech Tech Industry Insights Tech Innovation Tech Policy Technology News
    Share. Facebook Twitter Pinterest LinkedIn WhatsApp Reddit Tumblr Email
    Savannah Herald
    • Website

    Related Posts

    Tech May 13, 2026

    Protect your enterprise now from the Shai-Hulud worm and npm vulnerability in 6 actionable steps

    Tech May 12, 2026

    Some Women Are Obsessively Testing Their Vaginas to Optimize Them

    Tech May 12, 2026

    Videos: Robotic Hand Dexterity, Social Robots, and More

    Tech May 10, 2026

    EU Targets VPNs as Age Verification Loophole: Privacy vs. Protection in the Digital Age

    Business May 10, 2026

    How Brandeis Is Trying to Change College Shopping

    Tech May 10, 2026

    A new frontier: Identity stack evolves for agentic systems

    Comments are closed.

    Don't Miss
    Politics August 28, 2025By Savannah Herald03 Mins Read

    What America Made of Marx

    August 28, 2025

    National Politics Today: Information, Evaluation & Discussion Throughout the Range The bigger message of Marxism…

    Nvidia implicated of postponing RTX 5060 testimonials by keeping vehicle drivers

    August 29, 2025

    Pets Take Center Stage in Newhaven Court at Clearview Annual Dog Show

    April 24, 2026

    Newton County receives $1 million for water infrastructure upgrades

    April 15, 2026

    Global Ocean Summit in Nice ends with a raft of pledges for marine protection

    May 2, 2026
    Archives
    • May 2026
    • April 2026
    • March 2026
    • February 2026
    • January 2026
    • December 2025
    • November 2025
    • October 2025
    • September 2025
    • August 2025
    • July 2025
    • June 2025
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    Categories
    • Art & Literature
    • Beauty
    • Black History
    • Business
    • Climate
    • Education
    • Employment
    • Entertainment
    • Faith
    • Fashion
    • Food
    • Gaming
    • Georgia Politics
    • HBCUs
    • Health
    • Health Inspections
    • Investing
    • Lifestyle
    • Local
    • Lowcountry News
    • National
    • National Opinion
    • News
    • Politics
    • Real Estate
    • Senior Living
    • Sports
    • State
    • Tech
    • Transportation
    • Travel
    • World
    Savannah Herald Newsletter

    Subscribe to Updates

    A round up interesting pic’s, post and articles in the C-Port and around the world.

    About Us
    About Us

    The Savannah Herald is your trusted source for the pulse of Coastal Georgia and the Low County of South Carolina. We're committed to delivering timely news that resonates with the African American community.

    From local politics to business developments, we're here to keep you informed and engaged. Our mission is to amplify the voices and stories that matter, shining a light on our collective experiences and achievements.
    We cover:
    🏛️ Politics
    💼 Business
    🎭 Entertainment
    🏀 Sports
    🩺 Health
    💻 Technology
    Savannah Herald: Savannah's Black Voice 💪🏾

    Our Picks

    Biohacker Bryan Johnson Had Shock Therapy on Genitals for Erections

    August 28, 2025

    Mental Health Warnings on Social Media? Minnesota Will Require Them Next Year

    September 3, 2025

    New Senior Enrichment Center to serve the golden residents of Newton County

    March 21, 2026

    Shaw CIAA Women’s Tennis Championship Streak Hits Eight

    May 7, 2026

    CURTIS SYMONDS: PRESIDENT, CO-FOUNDER HBCU GO

    April 17, 2026
    Categories
    • Art & Literature
    • Beauty
    • Black History
    • Business
    • Climate
    • Education
    • Employment
    • Entertainment
    • Faith
    • Fashion
    • Food
    • Gaming
    • Georgia Politics
    • HBCUs
    • Health
    • Health Inspections
    • Investing
    • Lifestyle
    • Local
    • Lowcountry News
    • National
    • National Opinion
    • News
    • Politics
    • Real Estate
    • Senior Living
    • Sports
    • State
    • Tech
    • Transportation
    • Travel
    • World
    Copyright © 2002-2026 Savannahherald.com All Rights Reserved. A Veteran-Owned Business

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}
    Ad Blocker Enabled!
    Ad Blocker Enabled!
    Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

    Sign In or Register

    Welcome Back!

    Login below or Register Now.

    Lost password?

    Register Now!

    Already registered? Login.

    A password will be e-mailed to you.