Update: Ongoing Investigation and Additional Activity
ID: e2463843-c6eb-5cf8-b7c2-174dff39346a
STIX ID: report--e2463843-c6eb-5cf8-b7c2-174dff39346a
Feed Name: Aqua Security Blog
A supply-chain compromise of the open-source Trivy project and associated GitHub Actions was used to publish malicious releases and tamper with version tags, enabling an attacker to run code in downstream CI/CD pipelines that exfiltrated secrets (API tokens, cloud credentials, SSH/Kubernetes keys, etc.). The advisory details the timeline (initial token theft, tag force-pushes, malicious trivy v0.69.4 release), provides remediation steps (update to known-safe versions, rotate secrets, audit workflows, pin actions to SHAs), and lists IOCs and containment actions.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
