Trivy vulnerability scanner breach pushed infostealer via GitHub Actions

2026-03-22T13:23:36Zf7340de31104a23f91713f3dddabe893135f0947b7b23bb25b6ee377dc4ec3ee
azure-monitorbluenoroffbotnet-takedowncallback-phishingcisco-fmccredential-theftemergency-patchgithub-actionsincident-responseinfostealerlaw-enforcementlazarusmagento-polyshellmfanavia-data-breachoperation-aliceoracle-identity-managerpatchingrotate-credentialsrussian-intelligencesignal-phishingsupply-chain-attackteampcptrivyunauthenticated-rce

What happened

Multiple high-impact incidents reported: the Trivy vulnerability scanner was compromised in a supply‑chain attack by actors tracked as TeamPCP, distributing credential‑stealing malware via official releases and malicious GitHub Actions. Oracle issued an out‑of‑band emergency patch for a critical unauthenticated RCE (CVE-2026-21992) in Identity Manager/Web Services Manager, and CISA ordered federal agencies to urgently patch a maximum‑severity Cisco Secure FMC flaw (CVE-2026-20131). Additional threats include a new Magento 'PolyShell' unauthenticated RCE, abuse of Microsoft Azure Monitor alerts

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
f7340de31104a23f91713f3dddabe893135f0947b7b23bb25b6ee377dc4ec3ee
Enrichment time
2026-03-22T13:23:36Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Trivy vulnerability scanner breach pushed infostealer via GitHub Actions · Baitaphish