Latest News for: trivy

Edit

Trivy Supply Chain Attack Spreads, Triggers Self-Spreading CanisterWorm Across 47 npm Packages

Slashdot 22 Mar 2026
"We have removed all malicious artifacts from the affected registries and channels," Trivy maintainer Itay Shakury posted today, noting that all the latest Trivy releases "now point to a safe version."
Edit

Widely used Trivy scanner compromised in ongoing supply-chain attack

Ars Technica 21 Mar 2026
Hackers have compromised virtually all versions of Aqua Security’s widely used Trivy vulnerability scanner in an ongoing supply chain attack that could have wide-ranging consequences for developers and the organizations that use them.
Edit

From Scanner to Stealer: Inside the trivy-action Supply Chain Compromise (Crowdstrike Holdings Inc)

Public Technologies 20 Mar 2026
). The text version of this document is not available ... Disclaimer ... (noodl. 130337240) .
  • 1
×