Tag: Trivy GitHub


  • Trivy GitHub breach spreads infostealer via CI attack

    A supply chain incident has exposed serious weaknesses in CI/CD pipelines. The Trivy GitHub breach shows how attackers can exploit automation workflows to gain control over trusted projects. In this case, a security tool itself became the entry point, turning a defensive solution into a distribution channel for malicious code. Misconfigured Workflow Enabled Initial Access…