Trivy, an open-source tool for identifying vulnerabilities, has experienced a significant security breach for the second time in a month. This incident involved the GitHub Actions workflows 'aquasecurity/trivy-action' and 'aquasecurity/setup-trivy', which are essential for scanning Docker images for vulnerabilities and configuring CI/CD pipelines. The breach allowed attackers to hijack 75 tags, enabling them to deploy malicious code that targeted sensitive CI/CD secrets. The compromised tags were used to distribute malware, raising alarms about the security of CI/CD processes. Aqua Security has urged users to review their workflows and take necessary precautions to safeguard their systems. This incident highlights the ongoing risks associated with open-source tools and the importance of maintaining robust security practices in software development environments.
Trivy Security Scanner GitHub Actions Breach: 75 Tags Compromised to Exfiltrate CI/CD Secrets
Aqua Security's Trivy vulnerability scanner faced a breach, affecting GitHub Actions and leading to the hijacking of 75 tags to extract sensitive information.
