Trivy Supply Chain Compromise

AccuKnox pdf 2026-03-25T00:00:00

Abstract

Threat actor group TeamPCP has compromised the official Trivy release pipeline. Malicious versions v0.69.4 and v0.69.5 are live and actively exfiltrating credentials from affected CI/CD environments.

Loading executive summary...
Loading full markdown...

Your browser does not support inline PDF viewing.

Download the PDF to view it.

Match Rate: 10.00/10 (Relevance to core cybersecurity goals)

LINK COPIED TO CLIPBOARD