I repository GitHub Actions di Aqua Security per Trivy sono stati force-pushed e 75 tag sostituiti con versioni malevole. Il payload iniettato è stato eseguito sui runner di GitHub Actions e ha esfiltrato token GitHub/PAT, credenziali cloud, chiavi SSH e token Docker e Kubernetes.
Part of the PlainSec briefing for 2026-03-27
Every edition of this story: Compromissione di Trivy GitHub Actions Espone Segreti CI/CD