{
"$type": "site.standard.document",
"bskyPostRef": {
"cid": "bafyreigvn4c6xpji47utsfuelrre4gryg4psa7cm6xrxcfp55jobetvqhe",
"uri": "at://did:plc:6wtxqaikjf62unmnajbfbq5v/app.bsky.feed.post/3mhuwwhfrk2s2"
},
"coverImage": {
"$type": "blob",
"ref": {
"$link": "bafkreictrrsslpg7cyhdnc5x76p6deno3p5nupwa7yndt7xlpamccljvc4"
},
"mimeType": "image/webp",
"size": 10538
},
"path": "/trivy-supply-chain-attack-turns-aqua-security-scanner-into-a-secret-stealer/",
"publishedAt": "2026-03-25T08:19:51.000Z",
"site": "https://vpncentral.com",
"tags": [
"News",
"Trivy supply chain attack turns Aqua Security scanner into a secret stealer",
"VPN Central"
],
"textContent": "A supply chain attack against Aqua Security’s widely used Trivy scanner let attackers push malicious code into parts of the Trivy ecosystem and steal secrets from CI/CD environments. Aqua says the attackers used compromised credentials to publish a malicious Trivy v0.69.4 release, tamper with tags in trivy-action and setup-trivy, and later push malicious Docker Hub […]\n\nThe post Trivy supply chain attack turns Aqua Security scanner into a secret stealer appeared first on VPN Central.",
"title": "Trivy supply chain attack turns Aqua Security scanner into a secret stealer"
}