U.S. CISA adds an Aquasecurity Trivy flaw to its Known Exploited Vulnerabilities catalog
ID: 0e9ff771-c31a-55f1-9b76-365e0b0f4201
STIX ID: report--0e9ff771-c31a-55f1-9b76-365e0b0f4201
Feed Name: Security Affairs
CISA added CVE-2026-33634 — a high-severity (CVSS 9.3) Aquasecurity Trivy supply-chain compromise — to its Known Exploited Vulnerabilities catalog after attackers used stolen credentials to publish a malicious Trivy release (v0.69.4) and modify GitHub Actions to exfiltrate sensitive data on March 19–20, 2026. Affected artifacts include Trivy binaries, container images, and Actions; organizations are advised to remove compromised artifacts, rotate all secrets, review logs for suspicious activity, and pin GitHub Actions to immutable commit hashes. Federal agencies were ordered to remediate by April 9, 2026.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
