Experts warn of a ‘loud and aggressive’ extortion wave following Trivy hack

2026-03-24T20:51:43Zee2c3c5f1b283fec95dd26e1357b32d70787d1008d1a090712fd03c060afa536
aquacontainer-securitydownstream-impactextortionimage-scanningincident-responsemalicious-packageopen-source-compromiserepository-compromisesoftware-supply-chainsupply-chaintrivy

What happened

Attackers compromised the open-source container/image-scanning tool Trivy (Aqua) and pushed malicious versions to downstream users. Mandiant warns the fallout could affect up to ~10,000 downstream victims and trigger a “loud and aggressive” extortion wave targeting organizations that consumed the tainted releases. This is a high-impact software supply-chain compromise with broad downstream risk to CI/CD, container images, and software distribution; organizations should assume potential exposure if they used affected Trivy builds and prioritize verification of artifacts, rebuilds from trusted/­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
cyberscoop
Record identifier
ee2c3c5f1b283fec95dd26e1357b32d70787d1008d1a090712fd03c060afa536
Enrichment time
2026-03-24T20:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Experts warn of a ‘loud and aggressive’ extortion wave following Trivy hack · Baitaphish