logo

Experts warn of a ‘loud and aggressive’ extortion wave following Trivy hack

ID: a4456ef7-bdb2-5f73-9523-493ec6bc83a2

STIX ID: report--a4456ef7-bdb2-5f73-9523-493ec6bc83a2

Feed Name: CyberScoop

Threat Score
90/100

Date Published: 2026-03-24

Date Updated: 2026-04-21

Author: Matt Kapko

...
...

Mandiant and Aqua Security are responding to an active supply-chain attack that compromised Trivy by exploiting a GitHub Actions misconfiguration to steal a privileged access token and publish malicious releases on March 19; over 1,000 downstream SaaS environments are already impacted and the incident is expected to cause widespread follow-on breaches, extortion attempts, and additional compromises.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.