Cybersecurity & Privacy — 2026-03-23

Trivy Vulnerability Scanner Hit by Supply Chain Attack Spreading to Docker and GitHub

Aqua Security's popular open-source vulnerability scanner Trivy was compromised in a supply chain attack that spread malicious code to Docker containers and GitHub repositories. The attack deployed infostealers and, in Kubernetes environments, triggered a worm and wiper component. The campaign represents a significant compromise of security tooling infrastructure, as Trivy is widely used across DevOps and cloud-native environments for container and infrastructure scanning.

1 sources
  1. Aqua's Trivy Vulnerability Scanner Hit by Supply Chain Attack - SecurityWeek

View in full brief →

UNCLASSIFIED // OPEN SOURCE