Widely used Trivy scanner compromised in ongoing supply-chain attack
2026-03-23T08:51:49Z•9b48b27f94e655f8ee98e855293499ee5437165e0065b08788f1487e89af202d
AirSnitchCISADarkSwordIoTLLM-privacy-deanonymizationandroidcastleloadercredential-theftiOSinvisible-unicodeip-kvmlumma-stealermalicious-packagesmalwaremobile-exploitnotepad++patchingquantum-proof-httpsrouterssecure-bootstrykersupply-chaintrivywifiwiper
What happened
A broad set of high-impact security stories: multiple supply-chain compromises (including the widely used Trivy scanner, Notepad++, invisible/unicode-based attacks, and malicious packages targeting dYdX) are delivering backdoors and credential-stealing tooling, prompting secret rotations and urgent mitigations. Mobile and device threats are prominent — a powerful iPhone exploit/tool dubbed DarkSword is observed in the wild and CISA-listed iOS flaws remain active, while Wi‑Fi (AirSnitch), consumer security cameras, 14,000 infected routers, and IP‑KVM vulnerabilities expose large numbers of IoT/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- 9b48b27f94e655f8ee98e855293499ee5437165e0065b08788f1487e89af202d
- Enrichment time
- 2026-03-23T08:51:49Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.