The Lab 路 2026-03-25 05:56:50 路 GitHub Issues
A sophisticated supply chain attack has compromised the official GitHub repositories for Aqua Security's Trivy vulnerability scanner, with a threat actor using stolen credentials to publish malicious software releases and force-push dozens of version tags to credential-stealing malware. The attack targeted the core `aq...
The Lab 路 2026-03-25 05:56:51 路 GitHub Issues
A sophisticated supply chain attack has compromised the official GitHub Actions for Aqua Security's Trivy vulnerability scanner. Threat actors used stolen credentials to publish a malicious Trivy v0.69.4 release and then force-pushed 76 out of 77 version tags in the `aquasecurity/trivy-action` repository to credential-...
The Lab 路 2026-03-25 10:27:13 路 GitHub Issues
A GitHub repository's automated security scan has flagged high or critical vulnerabilities, triggering a formal security alert. The scan, conducted by the Trivy tool, specifically identified a security flaw within the project's `package-lock.json` file, a critical dependency manifest for Node.js applications. This auto...
The Lab 路 2026-03-28 05:27:02 路 GitHub Issues
A critical supply chain attack has compromised the official GitHub Actions for Aqua Security's Trivy vulnerability scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release and then force-pushed 76 out of 77 version tags in the `aquasecurity/trivy-action` repos...
The Lab 路 2026-03-28 05:27:05 路 GitHub Issues
A sophisticated supply chain attack has compromised the official GitHub Actions for Aqua Security's Trivy, a critical open-source security scanner used by millions of projects. Threat actors used stolen credentials to publish a malicious Trivy v0.69.4 release and then force-pushed 76 out of 77 version tags in the `aqua...
The Lab 路 2026-03-29 07:26:52 路 GitHub Issues
A Trivy vulnerability scan has flagged the widely used `ghcr.io/anthony-spruyt/megalinter-sungather:latest` container image as a significant security risk, revealing 47 total vulnerabilities including three rated CRITICAL and 16 rated HIGH. The scan, conducted on March 29, 2026, indicates the container is shipping with...
The Lab 路 2026-03-29 07:26:53 路 GitHub Issues
A recent Trivy security scan has exposed a significant vulnerability cluster within the `ghcr.io/anthony-spruyt/megalinter-xfg:latest` container image. The scan, dated March 29, 2026, identified 47 total vulnerabilities, including 3 rated CRITICAL and 16 rated HIGH. This concentration of severe flaws in a widely used d...
The Lab 路 2026-03-30 14:27:24 路 GitHub Issues
A routine security scan has flagged critical vulnerabilities within the Docker images of the 'memory-journal-mcp' project on GitHub. The automated scan, conducted by Trivy, triggered an immediate security alert, mandating urgent review and remediation. This discovery highlights the persistent risk of supply chain attac...
The Lab 路 2026-03-30 18:26:58 路 The Register
The threat actors behind the recent Trivy supply-chain breach have escalated their campaign, now poisoning the Python Package Index (PyPI) with malicious versions of the Telnyx SDK. This latest attack aims to infect developers' systems with credential-stealing malware, marking a continued and aggressive exploitation of...
The Lab 路 2026-03-31 08:27:10 路 GitHub Issues
A critical supply chain attack has compromised the official GitHub Actions for Trivy, a widely used open-source security scanner. On March 19, 2026, a threat actor used stolen credentials to publish a malicious version of Trivy (v0.69.4) and executed a sweeping hijack of the project's version history. The attacker forc...
The Lab 路 2026-03-31 08:27:11 路 GitHub Issues
A sophisticated supply chain attack has compromised the official GitHub Actions for Aqua Security's Trivy vulnerability scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release and force-push 76 out of 77 version tags in the `aquasecurity/trivy-action` reposit...
The Lab 路 2026-03-31 08:27:16 路 GitHub Issues
A critical supply chain attack has compromised the official GitHub Actions for Aqua Security's Trivy vulnerability scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release and then force-pushed 76 out of 77 version tags in the `aquasecurity/trivy-action` repos...
The Lab 路 2026-03-31 09:27:07 路 GitHub Issues
A sophisticated supply chain attack has compromised the core security tools of Aqua Security, a major player in the container and vulnerability scanning space. Threat actors used compromised credentials to publish malicious releases of the Trivy scanner and force-push nearly all version tags in its associated GitHub re...
The Lab 路 2026-03-31 10:27:06 路 GitHub Issues
A sophisticated supply chain attack has compromised the official GitHub Actions for Trivy, a critical open-source security scanner used by millions of repositories. Threat actors, using stolen credentials, successfully published malicious releases and force-pushed nearly all version tags for the `aquasecurity/trivy-act...
The Lab 路 2026-03-31 18:27:16 路 GitHub Issues
A sophisticated supply chain attack has compromised the official GitHub Actions for Aqua Security's Trivy, a critical open-source security scanner used by millions of repositories. Threat actors used stolen credentials to publish a malicious Trivy v0.69.4 release and then force-pushed 76 out of 77 version tags in the `...
The Lab 路 2026-03-31 19:27:16 路 GitHub Issues
A critical supply chain attack has compromised the official GitHub Actions for Trivy, a widely used open-source security scanner. On March 19, 2026, a threat actor used stolen credentials to publish a malicious Trivy v0.69.4 release and force-pushed 76 out of 77 version tags in the `aquasecurity/trivy-action` repositor...
The Lab 路 2026-04-02 05:26:59 路 GitHub Issues
A sophisticated supply chain attack has compromised the core security scanning tools of Aqua Security, directly targeting the widely used Trivy vulnerability scanner and its GitHub Actions. Threat actors, using compromised credentials, successfully published malicious releases and force-pushed nearly all version tags f...
The Lab 路 2026-04-02 15:27:30 路 GitHub Issues
A medium-severity security vulnerability, tracked as CVE-2025-59471, has been flagged by GitHub's CodeQL analysis in the `agentapi-plusplus` repository. The automated security scanning tool Trivy identified the issue under the `LanguageSpecificPackageVulnerability` rule, which is currently in an open state. This alert ...
The Lab 路 2026-04-02 19:27:03 路 GitHub Issues
A Trivy security scan has flagged five HIGH-severity vulnerabilities within a critical software component, exposing a potential attack surface for denial-of-service, arbitrary code execution, and information disclosure. The scan, conducted on April 2, 2026, targeted the `7002370412/news-feed:latest` container image, wh...
The Lab 路 2026-04-07 12:27:22 路 GitHub Issues
A routine security scan has flagged critical vulnerabilities within the Docker images for the Memory Journal MCP project. The automated scan, conducted by Trivy, triggered an immediate security alert, indicating the presence of exploitable flaws in the project's containerized environment. This discovery necessitates ur...