European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack

2026-04-04T13:24:06Z23675019d0fcafd43ff0370a69d4cd8804dec17e9a274060cc565e1a95ec7bc0
awsclaudecredential-harvestingcryptocurrency-heistdarksworddata-breachdriftexploit-kitgovernment-espionagemobile-securityransomwarereact2shellsharefilesource-code-leaksupply-chaintrivytrueconfunauthenticated-rcevulnerabilityzero-day

What happened

Multiple high-impact incidents and vulnerabilities were reported: the European Commission confirmed a supply-chain–linked data breach tied to Trivy that exposed over 300 GB of data in its AWS environment; a TrueConf zero-day was exploited by a Chinese actor against Asian government targets for reconnaissance, privilege escalation and payload deployment; critical ShareFile vulnerabilities can be chained to achieve unauthenticated RCE and arbitrary file upload; React2Shell was abused in a large credential-harvesting campaign compromising 750+ systems; North Korean actors drained $285M from Drift

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
23675019d0fcafd43ff0370a69d4cd8804dec17e9a274060cc565e1a95ec7bc0
Enrichment time
2026-04-04T13:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.