Trivy vulnerability scanner breach pushed infostealer via GitHub Actions
2026-03-22T01:23:29Z•d294904e723cf39d9d572bf3625c159505cb59abbc22fab90bc84d53a880e901
azure-monitorbluenoroffbotnet-takedowncallback-phishingciscocisco-fmccredential-theftcsam-takedowndata-breachgithub-actionsidentity-managerinfostealerlazarusmagentonaviaoperation-aliceoraclephishingpolyshellrcerussian-intelligencesignalsupply-chainteampcptrivy
What happened
Multiple high-impact security events: the Trivy vulnerability scanner was compromised in a supply‑chain attack by threat actor 'TeamPCP', which pushed credential‑stealing malware via official releases and GitHub Actions; Microsoft Azure Monitor alerts are being abused for callback phishing; the FBI links Signal/WhatsApp phishing campaigns to Russian intelligence‑linked actors; Oracle issued an out‑of‑band fix for a critical unauthenticated RCE (CVE-2026-21992); CISA ordered federal agencies to urgently patch a max‑severity Cisco Secure FMC flaw (CVE-2026-20131); a new 'PolyShell' unauth RCE is
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- d294904e723cf39d9d572bf3625c159505cb59abbc22fab90bc84d53a880e901
- Enrichment time
- 2026-03-22T01:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.