Trivy Tag Compromise Supply Chain Attack
ID: a3be69bf-35f3-5e7c-af8f-6ddceaab171d
STIX ID: report--a3be69bf-35f3-5e7c-af8f-6ddceaab171d
Feed Name: Kudelski Security
Trivy's release process was compromised when attackers reassigned the v0.69.4 Git tag to malicious commits and published a release containing binaries that collect environment variables, configuration data, and CI secrets and exfiltrate them to attacker infrastructure; this active supply-chain attack can propagate broadly via automated CI/CD and developer workflows, and recommended mitigations include avoiding unverified tags, pinning commit SHAs, enforcing tag/release protections, rotating exposed secrets, and validating releases via checksums or cryptographic signatures.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
