Trivy’s March Supply Chain Attack Shows Where Secret Exposure Hurts Most

The Trivy story is moving quickly, and the latest reporting makes one thing clear: this is no longer just a GitHub Actions tag hijack. What started as a compromise of trivy-action, setup-trivy, and the v0.69.4 release has expanded into malicious Docker Hub images.

The post Trivy’s March Supply Chain Attack Shows Where Secret Exposure Hurts Most appeared first on Security Boulevard.

This article has been indexed from Security Boulevard

Read the original article: