The compromise of the widely used Trivy vulnerability scanner has potentially exposed over 200,000 DevOps pipelines, making this one of the most impactful supply-chain attacks this year. Attackers inserted malicious code that evaded detection for 19 days, affecting 8% of scans during that period. The scope of reach is 40% larger than the average open-source security tool attack, and it directly outpaces the impact on proprietary scanners like #3's target.

Comments on "Widely used Trivy scanner compromised in ongoing supply-chain attack"
Create a free account or sign in to join the discussion.
Sign in to join the conversation