Trivy vulnerability scanner breach pushed infostealer via GitHub Actions
2026-03-22T07:23:29Z•6d4597895fcbe979c443e436ed094b757780e9ce9b53219aebfbdfe04004b9d4
Azure MonitorCISACSAM/Operation-Alice','Android','sideloading','Advanced-Flow','vCVE-2026-20131CVE-2026-21992CiscoDDoSGitHub ActionsLazarus/BluenoroffMagentoNaviaOraclePolyShellRCERussian-intelligenceSignalTeamPCPTrivybotnetcallback-phishingcredential-theftdata-breachinfostealerphishingsupply-chain
What happened
A batch of security incidents and updates: The Trivy vulnerability scanner was compromised in a supply‑chain attack by a group called TeamPCP, which distributed credential‑stealing malware via official releases and GitHub Actions; Google introduced an “Advanced Flow” for safer APK sideloading; Microsoft Azure Monitor alerts are being abused to send callback phishing messages while the FBI links targeted Signal/WhatsApp phishing to Russian intelligence actors; Oracle released an out‑of‑band emergency patch for a critical unauthenticated RCE (CVE‑2026‑21992); CISA ordered federal agencies to hot
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 6d4597895fcbe979c443e436ed094b757780e9ce9b53219aebfbdfe04004b9d4
- Enrichment time
- 2026-03-22T07:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.