Tech giants under attack by a Trivy-compromised GitHub action.
Cisco – More than 300 GitHub repositories were cloned during the incident, including source code for its AI-powered products, such as AI Assistants, AI Defense, and unreleased products. A portion of the stolen repositories allegedly belongs to corporate customers, including banks, BPOs, and US government agencies.
https://www.bleepingcomputer.com/news/security/cisco-source-code-stolen-in-trivy-linked-dev-environment-breach/
Post #2649
3.98K
DevOps & SRE notes 🚨 Trivy has been hacked, again. --- What happened? Attackers compromised the official aquasecurity/trivy-action GitHub Action — the one people use to run Trivy vulnerability scans in CI/CD pipelines. This was disclosed today (March 20, 2026). It's the…
- 👏 5
- ❤ 1