European Commission Confirms Data Breach Linked to Trivy Supply Chain Attack
2026-04-04T13:24:06Z•23675019d0fcafd43ff0370a69d4cd8804dec17e9a274060cc565e1a95ec7bc0
awsclaudecredential-harvestingcryptocurrency-heistdarksworddata-breachdriftexploit-kitgovernment-espionagemobile-securityransomwarereact2shellsharefilesource-code-leaksupply-chaintrivytrueconfunauthenticated-rcevulnerabilityzero-day
What happened
Multiple high-impact incidents and vulnerabilities were reported: the European Commission confirmed a supply-chain–linked data breach tied to Trivy that exposed over 300 GB of data in its AWS environment; a TrueConf zero-day was exploited by a Chinese actor against Asian government targets for reconnaissance, privilege escalation and payload deployment; critical ShareFile vulnerabilities can be chained to achieve unauthenticated RCE and arbitrary file upload; React2Shell was abused in a large credential-harvesting campaign compromising 750+ systems; North Korean actors drained $285M from Drift
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 23675019d0fcafd43ff0370a69d4cd8804dec17e9a274060cc565e1a95ec7bc0
- Enrichment time
- 2026-04-04T13:24:06Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.