Trivy: Vulnerability Scanner
Trivy is a comprehensive vulnerability scanner developed by Aqua Security. It was the initial target of the TeamPCP supply-chain attack, with malicious…
Trivy is a comprehensive vulnerability scanner developed by Aqua Security. It was the initial target of the TeamPCP supply-chain attack, with malicious…
Two malicious LiteLLM releases on PyPI, versions 1.82.7 and 1.82.8, were live for about 40 minutes on March 24, 2026, carrying credential-stealing…
CVE-2026-33634 is a critical vulnerability in the Trivy scanner ecosystem, exploited in a supply-chain attack that also affected LiteLLM. Added to CISA's…
Aqua Security is the developer of the Trivy scanner, which was compromised in the TeamPCP campaign. The company reported that attackers retained…
trivy-action is a GitHub Action for running Trivy vulnerability scans. It was compromised in a 2026 tag hijack attack, which this research…