Trivy Supply Chain Attack Expands as Compromised Docker Images Hit Docker Hub

A supply chain attack targeting Trivy, the widely used open-source vulnerability scanner, has grown well beyond its initial scope. What started as a GitHub Actions compromise has now extended to Docker Hub, where three malicious Docker image versions were silently published and made publicly available to developers worldwide. Trivy is trusted by thousands of DevSecOps […]

The post Trivy Supply Chain Attack Expands as Compromised Docker Images Hit Docker Hub appeared first on Cyber Security News.

This article has been indexed from Cyber Security News

Read the original article: