TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences for their alleged roles…
The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences for their alleged roles…
Trivy, an open-source security scanner, was compromised in March 2026. Credentials stolen from Trivy were used to compromise Checkmarx KICS actions.
Two malicious LiteLLM releases on PyPI, versions 1.82.7 and 1.82.8, were live for about 40 minutes on March 24, 2026, carrying credential-stealing…
CVE-2026-33634 is a critical vulnerability in the Trivy scanner ecosystem, exploited in a supply-chain attack that also affected LiteLLM. Added to CISA's…
Aqua Security is the developer of the Trivy scanner, which was compromised in the TeamPCP campaign. The company reported that attackers retained…
trivy-action is a GitHub Action for running Trivy vulnerability scans. It was compromised in a 2026 tag hijack attack, which this research…