Trivy stories
Sonatype warns of surge in trusted open-source malware
3 days ago
#
application security
#
devsecops
#
supply chain
Sonatype flags 21,764 malicious open-source packages in Q1 2026, with npm hit hardest as attackers used trusted workflows to steal secrets.
AppOmni adds Heisenberg mode after LiteLLM supply attack
Last month
#
virtualisation
#
cloud security
#
application security
AppOmni upgrades Heisenberg to help teams trace GitHub Actions and spot tainted dependencies after the LiteLLM supply chain breach.
Trivy GitHub breach exposes CI/CD supply chain risk
Last month
#
devops
#
cloud security
#
application security
Aqua Security's Trivy GitHub Action was hijacked to ship infostealer code via CI/CD pipelines, exposing secrets across downstream users.
JFrog flags 13 critical CI/CD flaws in GitHub workflows
Last month
#
siem
#
fintech
#
application security
JFrog warns 13 GitHub CI/CD workflow flaws, mostly critical, could let attackers hijack pipelines and steal secrets at scale.
Aqua Security expands Trivy for Kubernetes vulnerability scanning & KBOM generation
Wed, 8th Nov 2023
#
application security
#
open source
#
red hat
Aqua Security enhances its open-source solution, Trivy, to offer Kubernetes vulnerability scanning and Kubernetes Bill of Materials generation.
Aqua Security incorporates CIS Kubernetes benchmarks scanning into open source Trivy
Thu, 20th Apr 2023
#
virtualisation
#
application security
#
open source
Aqua Security's Aqua Trivy now offers full compliance scanning for CIS Kubernetes Benchmarks, simplifying security for cloud native applications.
Aqua Security adds CPSM capabilities to Aqua Trivy
Thu, 18th Aug 2022
#
cloud security
#
application security
#
open source
Aqua Security has added cloud security posture management (CPSM) capabilities to its open source tool, Aqua Trivy.
Aqua Security createa unified scanner for cloud native security
Fri, 20th May 2022
#
devops
#
cloud security
#
application security
Aqua Security's Trivy becomes world's first unified scanner for cloud native security, consolidating multiple tools into one.