BT
Privacy ToolboxJournalProjectsResumeBookmarks
Feed
Privacy Toolbox
Journal
Projects
Resume
Bookmarks
Intel
CIPHER
Threat Actors
Privacy Threats
Dashboard
CVEs
Tags
Intel
CIPHERThreat ActorsPrivacy ThreatsDashboardCVEsTags

Intel

  • Feed
  • Threat Actors
  • Privacy Threats
  • Dashboard
  • Privacy Toolbox
  • CVEs

Personal

  • Journal
  • Projects

Resources

  • Subscribe
  • Bookmarks
  • Developers
  • Tags
Cybersecurity News & Analysis
github
defconxt
•
© 2026
•
blacktemple.net
  1. Feed
  2. /Tags
  3. /github-actions

Tag: github-actions

criticalVulnerabilities & Exploits

Critical Supply Chain Attacks Hit Trivy Scanner While CISA Adds 5 CVEs to KEV Catalog

Threat actors compromised Trivy vulnerability scanner multiple times, deploying self-propagating CanisterWorm malware across 47 npm packages and stealing CI/CD secrets from GitHub Actions. Meanwhile, CISA added 5 actively exploited vulnerabilities affecting Apple, Craft CMS, and Laravel to its KEV catalog with an April 3rd patching deadline.

Mar 21, 2026The Hacker News, Microsoft Security, MSRC Security Updates
supply-chain-attackstrivynpm-packages
🇺🇸Apple
criticalCloud Security

Supply Chain Attack Compromises Aqua Security's Trivy Scanner

TeamPCP threat actors injected credential-stealing malware into Aqua Security's popular Trivy vulnerability scanner and related GitHub Actions. Organizations using Trivy need to immediately audit their environments for potential credential compromise.

Mar 21, 2026Wiz Blog
supply-chain-attacktrivycredential-theft