WhisperX tag archive

#Trivy

This page collects WhisperX intelligence signals tagged #Trivy. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (20)

The Lab 路 2026-03-25 05:56:50 路 GitHub Issues

1. Aqua Security Trivy GitHub Action Compromised: Malicious Tags Force-Pushed in Supply Chain Attack

A sophisticated supply chain attack has compromised the official GitHub repositories for Aqua Security's Trivy vulnerability scanner, with a threat actor using stolen credentials to publish malicious software releases and force-push dozens of version tags to credential-stealing malware. The attack targeted the core `aq...

The Lab 路 2026-03-25 05:56:51 路 GitHub Issues

2. Aqua Security Trivy GitHub Action Compromised: Malicious Tags Force-Pushed in Supply Chain Attack

A sophisticated supply chain attack has compromised the official GitHub Actions for Aqua Security's Trivy vulnerability scanner. Threat actors used stolen credentials to publish a malicious Trivy v0.69.4 release and then force-pushed 76 out of 77 version tags in the `aquasecurity/trivy-action` repository to credential-...

The Lab 路 2026-03-25 10:27:13 路 GitHub Issues

3. GitHub Security Alert: High/Critical Vulnerabilities Detected in Automated Trivy Scan

A GitHub repository's automated security scan has flagged high or critical vulnerabilities, triggering a formal security alert. The scan, conducted by the Trivy tool, specifically identified a security flaw within the project's `package-lock.json` file, a critical dependency manifest for Node.js applications. This auto...

The Lab 路 2026-03-28 05:27:02 路 GitHub Issues

4. Aqua Security Trivy GitHub Action Compromised: Malicious Tags Force-Pushed in Supply Chain Attack

A critical supply chain attack has compromised the official GitHub Actions for Aqua Security's Trivy vulnerability scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release and then force-pushed 76 out of 77 version tags in the `aquasecurity/trivy-action` repos...

The Lab 路 2026-03-28 05:27:05 路 GitHub Issues

5. Aqua Security Trivy Action Compromised: Malicious Tags Force-Pushed in Major Supply Chain Attack

A sophisticated supply chain attack has compromised the official GitHub Actions for Aqua Security's Trivy, a critical open-source security scanner used by millions of projects. Threat actors used stolen credentials to publish a malicious Trivy v0.69.4 release and then force-pushed 76 out of 77 version tags in the `aqua...

The Lab 路 2026-03-29 07:26:52 路 GitHub Issues

6. Trivy Scan Exposes 3 Critical, 16 High Vulnerabilities in 'megalinter-sungather' Container

A Trivy vulnerability scan has flagged the widely used `ghcr.io/anthony-spruyt/megalinter-sungather:latest` container image as a significant security risk, revealing 47 total vulnerabilities including three rated CRITICAL and 16 rated HIGH. The scan, conducted on March 29, 2026, indicates the container is shipping with...

The Lab 路 2026-03-29 07:26:53 路 GitHub Issues

7. Megalinter-xfg Container Exposed: 3 Critical, 16 High Vulnerabilities Found in Latest Image

A recent Trivy security scan has exposed a significant vulnerability cluster within the `ghcr.io/anthony-spruyt/megalinter-xfg:latest` container image. The scan, dated March 29, 2026, identified 47 total vulnerabilities, including 3 rated CRITICAL and 16 rated HIGH. This concentration of severe flaws in a widely used d...

The Lab 路 2026-03-30 14:27:24 路 GitHub Issues

8. 馃毃 Security Vulnerabilities Detected in Docker Images for 'memory-journal-mcp' Project

A routine security scan has flagged critical vulnerabilities within the Docker images of the 'memory-journal-mcp' project on GitHub. The automated scan, conducted by Trivy, triggered an immediate security alert, mandating urgent review and remediation. This discovery highlights the persistent risk of supply chain attac...

The Lab 路 2026-03-30 18:26:58 路 The Register

9. PyPI Poisoning: Trivy Attackers Strike Again with Malicious Telnyx Package

The threat actors behind the recent Trivy supply-chain breach have escalated their campaign, now poisoning the Python Package Index (PyPI) with malicious versions of the Telnyx SDK. This latest attack aims to infect developers' systems with credential-stealing malware, marking a continued and aggressive exploitation of...

The Lab 路 2026-03-31 08:27:10 路 GitHub Issues

10. GitHub Action Compromise: Malicious Trivy v0.69.4 Release & Tag Hijack Exposes Supply Chain

A critical supply chain attack has compromised the official GitHub Actions for Trivy, a widely used open-source security scanner. On March 19, 2026, a threat actor used stolen credentials to publish a malicious version of Trivy (v0.69.4) and executed a sweeping hijack of the project's version history. The attacker forc...

The Lab 路 2026-03-31 08:27:11 路 GitHub Issues

11. Aqua Security Trivy Action Compromised: Malicious Tags Force-Pushed in GitHub Supply Chain Attack

A sophisticated supply chain attack has compromised the official GitHub Actions for Aqua Security's Trivy vulnerability scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release and force-push 76 out of 77 version tags in the `aquasecurity/trivy-action` reposit...

The Lab 路 2026-03-31 08:27:16 路 GitHub Issues

12. Aqua Security Trivy GitHub Action Compromised: Malicious Tags Force-Pushed in Supply Chain Attack

A critical supply chain attack has compromised the official GitHub Actions for Aqua Security's Trivy vulnerability scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release and then force-pushed 76 out of 77 version tags in the `aquasecurity/trivy-action` repos...

The Lab 路 2026-03-31 09:27:07 路 GitHub Issues

13. Aqua Security Trivy Supply Chain Attack: Malicious Releases & Credential-Stealing Tags Force-Pushed to GitHub

A sophisticated supply chain attack has compromised the core security tools of Aqua Security, a major player in the container and vulnerability scanning space. Threat actors used compromised credentials to publish malicious releases of the Trivy scanner and force-push nearly all version tags in its associated GitHub re...

The Lab 路 2026-03-31 10:27:06 路 GitHub Issues

14. GitHub Action Compromise: Malicious Trivy Releases & Tags Force-Pushed in Major Supply Chain Attack

A sophisticated supply chain attack has compromised the official GitHub Actions for Trivy, a critical open-source security scanner used by millions of repositories. Threat actors, using stolen credentials, successfully published malicious releases and force-pushed nearly all version tags for the `aquasecurity/trivy-act...

The Lab 路 2026-03-31 18:27:16 路 GitHub Issues

15. Aqua Security Trivy Action Compromised: Malicious Tags Force-Pushed in Major Supply Chain Attack

A sophisticated supply chain attack has compromised the official GitHub Actions for Aqua Security's Trivy, a critical open-source security scanner used by millions of repositories. Threat actors used stolen credentials to publish a malicious Trivy v0.69.4 release and then force-pushed 76 out of 77 version tags in the `...

The Lab 路 2026-03-31 19:27:16 路 GitHub Issues

16. GitHub Action Compromised: Malicious Trivy v0.69.4 Release and Tag Hijack Exposed

A critical supply chain attack has compromised the official GitHub Actions for Trivy, a widely used open-source security scanner. On March 19, 2026, a threat actor used stolen credentials to publish a malicious Trivy v0.69.4 release and force-pushed 76 out of 77 version tags in the `aquasecurity/trivy-action` repositor...

The Lab 路 2026-04-02 05:26:59 路 GitHub Issues

17. Aqua Security Trivy Supply Chain Attack: Malicious Releases & Credential-Stealing Tags Force-Pushed to GitHub Actions

A sophisticated supply chain attack has compromised the core security scanning tools of Aqua Security, directly targeting the widely used Trivy vulnerability scanner and its GitHub Actions. Threat actors, using compromised credentials, successfully published malicious releases and force-pushed nearly all version tags f...

The Lab 路 2026-04-02 15:27:30 路 GitHub Issues

18. GitHub CodeQL Flags Medium-Severity Vulnerability CVE-2025-59471 in KooshaPari/agentapi-plusplus

A medium-severity security vulnerability, tracked as CVE-2025-59471, has been flagged by GitHub's CodeQL analysis in the `agentapi-plusplus` repository. The automated security scanning tool Trivy identified the issue under the `LanguageSpecificPackageVulnerability` rule, which is currently in an open state. This alert ...

The Lab 路 2026-04-02 19:27:03 路 GitHub Issues

19. Security Alert: 5 HIGH Vulnerabilities Found in 'news-feed' Container, Including Critical libpng Flaws

A Trivy security scan has flagged five HIGH-severity vulnerabilities within a critical software component, exposing a potential attack surface for denial-of-service, arbitrary code execution, and information disclosure. The scan, conducted on April 2, 2026, targeted the `7002370412/news-feed:latest` container image, wh...

The Lab 路 2026-04-07 12:27:22 路 GitHub Issues

20. 馃毃 Security Vulnerabilities Detected in Memory Journal MCP Docker Images, Action Required

A routine security scan has flagged critical vulnerabilities within the Docker images for the Memory Journal MCP project. The automated scan, conducted by Trivy, triggered an immediate security alert, indicating the presence of exploitable flaws in the project's containerized environment. This discovery necessitates ur...