Trivy GitHub Actions Compromise Exposes CI/CD Secrets

Aqua Security's Trivy GitHub Actions repositories were force-pushed and 75 tags replaced with malicious versions. The injected payload ran in GitHub Actions runners and exfiltrated CI/CD and developer secrets.

Part of the PlainSec briefing for 2026-03-27

Sources