Widely used Trivy scanner compromised in ongoing supply-chain attack
2026-03-21T08:51:50Z•c208153c18bf58fe12dce9d0b667bb1ac0d7c8aae53637be49ce2dee2c2239dd
AirSnitchAsusCISADarkSwordIP-KVMLLM-deanonymizationLummaNotepad++StrykerTrivyWi‑Ficertificate-expirycryptocurrency-theftdYdXexploits-in-the-wildfirmwareiOSiPhonemalwarepassword-managersrouterssecure-bootsupply-chainunicode-obfuscationwiper
What happened
Collection of recent Ars Technica security reports highlighting an active, broad threat landscape: an ongoing supply‑chain compromise of the Trivy scanner and other repo/package backdoors (including invisible/unicode obfuscation and a Notepad++ updater compromise); powerful iPhone exploit set (DarkSword) and CISA‑tracked iOS flaws being used in the wild; targeted wiper attacks (Stryker), large-scale router infections (Asus devices), and renewed malware campaigns (Lumma Stealer, malicious dYdX packages). Additional notable issues include a new Wi‑Fi bypass (AirSnitch), problems with password‑m²
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- c208153c18bf58fe12dce9d0b667bb1ac0d7c8aae53637be49ce2dee2c2239dd
- Enrichment time
- 2026-03-21T08:51:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.