Trivy vulnerability scanner breach pushed infostealer via GitHub Actions
2026-03-21T19:23:29Z•a0a02bbc389c3de04e981287d6bf4358251ec7550175ce487cba98c8b9e6baa0
AisuruAzure-MonitorBluenoroffCISACVE-2026-20131CVE-2026-21992CiscoGitHub-ActionsJackSkidKimWolfLazarusMagentoMossad-botnet-disruption','data-breach','Navia','Operation-AliceOraclePolyShellRussian-intelligenceSignal-phishingTeamPCPTrivybotnet-takedowncallback-phishinginfostealerphishingsupply-chainunauthenticated-RCE
What happened
Multiple high-impact security events reported: the Trivy vulnerability scanner was compromised in a supply‑chain attack by the actor group dubbed TeamPCP, distributing credential‑stealing malware via official releases and GitHub Actions; Oracle issued an out‑of‑band emergency fix for a critical unauthenticated RCE in Identity Manager (CVE-2026-21992); CISA ordered federal agencies to urgently patch a maximum‑severity Cisco Secure FMC flaw (CVE-2026-20131). Additional notable items include a new unauthenticated Magento/Adobe Commerce RCE dubbed “PolyShell,” abuse of Microsoft Azure Monitor to送/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- a0a02bbc389c3de04e981287d6bf4358251ec7550175ce487cba98c8b9e6baa0
- Enrichment time
- 2026-03-21T19:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.