/s But I thought npm was the issue, and all of this couldn't happen anywhere else?!
Trivy under attack again: Widespread GitHub Actions tag compromise secrets
11–20 of 97 posts
Re: Trivy under attack again: Widespread GitHub Actions tag compromise secrets
#12Wasn't this discovered already last week, on Friday, that the threat actor had replaced the legit images with malware images? And republished 75 out of 76 tags?
Re: Trivy under attack again: Widespread GitHub Actions tag compromise secrets
#13Re: Trivy under attack again: Widespread GitHub Actions tag compromise secrets
#14I always run such tools inside sandboxes to limit the blast radius.
Re: Trivy under attack again: Widespread GitHub Actions tag compromise secrets
#15Friendly reminder that just because someone is building security software it doesn't mean they are competent and won't cause more harm than good. Every month the security team wants me to give full code or cloud access to some new scanner they want to trial. They love the fancy dashboards and lengthy reports but if I allowed just 10% of what they wanted we would be pwned on the regular...
Aqua were breached earlier this month, failed to contain it, got breached again last week, failed to contain it again, and now the attackers have breached their Docker Hub account. Shit happens but they're clearly not capable of handling this and should be enlisting outside help.
Re: Trivy under attack again: Widespread GitHub Actions tag compromise secrets
#16Re: Trivy under attack again: Widespread GitHub Actions tag compromise secrets
#17I always run such tools inside sandboxes to limit the blast radius.