Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack

Summary

Recapping the March 2026 Trivy compromise: TeamPCP injected malware into the scanner, trivy-action, and setup-trivy, and later fake Docker Hub images, harvesting cloud and CI/CD credentials.
Published
Collected

original ↗

Related coverage

back