GeistHaus
log in · sign up

Trivy Compromised a Second Time - Malicious v0.69.4 Release, aquasecurity/setup-trivy, aquasecurity/trivy-action GitHub Actions Compromised - StepSecurity

stepsecurity.io

On March 19, 2026, trivy — a widely used open source vulnerability scanner maintained by Aqua Security — experienced a second security incident. Three weeks after the hackerbot-claw incident on February 28 that resulted in a repository takeover, a new compromised release (v0.69.4) was published to the trivy repository. The original incident disclosure discussion (#10265) was also deleted during this period, and version tags on the aquasecurity/setup-trivy GitHub Action were removed. Trivy maintainers deleted the v0.69.4 tag and Homebrew downgraded to v0.69.3. The following is a factual account of what we observed through public GitHub data.

9 pages link to this URL
Attackers are now targeting your AI coding tool · Siddhant Khare

The Bitwarden CLI supply chain attack explicitly hunted Claude Code, Cursor, and Codex CLI configs. The same week, DPRK confirmed slopsquatting works in the wild. Here is what happened and what to do.

0 inbound links article en securitysupply-chainmcpagent-traceslopsquattingSiddhant KhareAI agent infrastructureLLM agentsagentic AIAI securityOpenFGACNCFmemory systemsauthorizationReBACagent orchestrationcontext engineeringcontext efficiencyRAG deduplicationKV-cacheinference optimizationsoftware engineeropen sourceGitpodOnamachine learning infrastructureZanzibar authorizationdistributed systemsGPU profilingMCP servers
GitHub - step-security/harden-runner: Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in real-time.

Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. It monitors network egress, file integrity, and process activity on those runners, detecting threats in re...

13 inbound links object en repository:422287306
Auditing my local Python packages

Python's virtual environments mean I can have many versions of the same package scattered across my machine. I've started keeping a list of my environments so I can see exactly what's installed, and where.

0 inbound links article en CC BY 4.0