ADVERTISEMENT
  • Home
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions
Sunday, March 22, 2026
  • Login
Vegas Valley News
Bisaya Language: My Favorite Job
Satorre
Buy Now
ADVERTISEMENT
  • Home
  • World News
  • Business
  • Sports
  • Health
  • Technology
  • Entertainment
  • Travel
  • Lifestyle
  • Vegas Valley News asks for your consent to use your personal data to:
  • VVN Opt out of the sale or sharing of personal information
No Result
View All Result
No Result
View All Result
  • Home
  • World News
  • Business
  • Sports
  • Health
  • Technology
  • Entertainment
  • Travel
  • Lifestyle
  • Vegas Valley News asks for your consent to use your personal data to:
  • VVN Opt out of the sale or sharing of personal information
Sunday, March 22, 2026
No Result
View All Result
Vegas Valley News
No Result
View All Result
Home Technology

Broadly used Trivy scanner compromised in ongoing supply-chain assault

by Vegas Valley News
March 22, 2026
in Technology
0
Broadly used Trivy scanner compromised in ongoing supply-chain assault
0
SHARES
0
VIEWS
Share on FacebookShare on Twitter



Hackers have compromised just about all variations of Aqua Safety’s broadly used Trivy vulnerability scanner in an ongoing provide chain assault that might have wide-ranging penalties for builders and the organizations that use them.

Trivy maintainer Itay Shakury confirmed the compromise on Friday, following rumors and a thread, since deleted by the attackers, discussing the incident. The assault started within the early hours of Thursday. When it was carried out, the risk actor had used stolen credentials to force-push all however one of many trivy-action tags and 7 setup-trivy tags to make use of malicious dependencies.

Assume your pipelines are compromised

A compelled push is a git command that overrides a default security mechanism that protects towards overwriting present commits. Trivy is a vulnerability scanner that builders use to detect vulnerabilities and inadvertently hardcoded authentication secrets and techniques in pipelines for creating and deploying software program updates. The scanner has 33,200 stars on GitHub, a excessive ranking that signifies it’s used broadly.

“For those who suspect you had been working a compromised model, deal with all pipeline secrets and techniques as compromised and rotate instantly,” Shakury wrote.

Safety corporations Socket and Wiz mentioned that the malware, triggered in 75 compromised trivy-action tags, causes customized malware to totally scour improvement pipelines, together with developer machines, for GitHub tokens, cloud credentials, SSH keys, Kubernetes tokens, and no matter different secrets and techniques could dwell there. As soon as discovered, the malware encrypts the information and sends it to an attacker-controlled server.

The tip consequence, Socket mentioned, is that any CI/CD pipeline utilizing software program that references compromised model tags executes code as quickly because the Trivy scan is run. Spoofed model tags embody the broadly used @0.34.2, @0.33, and @0.18.0. Model @0.35.0 seems to be the one one unaffected.

Tags: attackcompromisedongoingscannersupplychainTrivywidely
Vegas Valley News

Vegas Valley News

Vegas Valley News Local, Breaking News

Next Post
Warner Music Group inks unique Netflix deal to make artist and songwriter documentaries

Warner Music Group inks unique Netflix deal to make artist and songwriter documentaries

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recommended

Elon Musk rearranges Israel go to

Elon Musk rearranges Israel go to

2 weeks ago
Sharp fall in new residence gross sales after restrictions imposed

Sharp fall in new residence gross sales after restrictions imposed

9 months ago

Popular News

  • ‘Flesh-Consuming’ Micro organism Circumstances Rising on Gulf Coast: What to Know

    ‘Flesh-Consuming’ Micro organism Circumstances Rising on Gulf Coast: What to Know

    0 shares
    Share 0 Tweet 0
  • James Gunn Nonetheless ‘Working On’ Viola Davis-Led Amanda Waller Sequence

    0 shares
    Share 0 Tweet 0
  • ‘John Sweet: I Like Me’ trailer — Canadian actor’s life explored in documentary

    0 shares
    Share 0 Tweet 0
  • Keep Vancouver Promotion: As much as $250 Off Vancouver Accommodations!

    0 shares
    Share 0 Tweet 0
  • Sonam Kapoor, Arjun Kapoor and Extra Attend Anshula Kapoor’s Engagement Ceremony

    0 shares
    Share 0 Tweet 0

About Us

Vegas Valley News, based in Las Vegas, Nevada, is your go-to source for local news and events. Stay updated with the latest happenings in our vibrant community. For advertising opportunities, contact us at sales@vegasvalleynews.com. Your connection to the pulse of Vegas!

Category

  • Business
  • Entertainment
  • Health
  • Lifestyle
  • Sports
  • Technology
  • Travel
  • World

Recent Posts

  • Final Boomer Trivia Quiz: Check Your Information
  • Have a Stress-free Weekend. | Cup of Jo
  • The best way to Practice Your Mind to Be Extra Affected person
  • Home
  • Contact Us
  • Disclaimer
  • Privacy Policy
  • Terms & Conditions

Copyright © 2024 Vegasvalleynews.com | All Rights Reserved.

No Result
View All Result
  • Home
  • World News
  • Business
  • Sports
  • Health
  • Technology
  • Entertainment
  • Travel
  • Lifestyle
  • Vegas Valley News asks for your consent to use your personal data to:
  • VVN Opt out of the sale or sharing of personal information

Copyright © 2024 Vegasvalleynews.com | All Rights Reserved.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Verified by MonsterInsights