logo

CERT-EU Confirms Trivy Supply Chain Attack Led to European Commission AWS Breach

ID: 264ad128-6d82-5ab1-b368-2416e7b6478f

STIX ID: report--264ad128-6d82-5ab1-b368-2416e7b6478f

Feed Name: cybersecurityNews.com

Threat Score
90/100

Date Published: 2026-04-03

Date Updated: 2026-05-05

Author: Guru Baran

...
...

**Executive summary:** A supply-chain compromise of the open-source scanner Trivy allowed TeamPCP to obtain AWS secrets and exfiltrate ~340 GB of uncompressed data from the European Commission’s hosting environment (impacting up to 71 clients); the dataset was later published by the extortion group ShinyHunters, exposing personal data and outbound email files and prompting CERT-EU coordinated incident response and remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.