Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets

2026-03-21T07:24:07Z5232234c1ac9ecc1c81acb0c24ee2c1feb7672f10ced499629e8a988996f9f23
AI sandbox escapeAndroid banking malwareBYOVD / EDR evasionCI/CD secretsCVE-2026-20131CVE-2026-20643CVE-2026-32746CVE-2026-33017CVE-2026-3888Cisco FMCDNS data exfiltrationDarkSwordGitHub ActionsIoT botnetsLangflowPerseusTrivyWebKitactive exploitationiOS exploit kitprivilege escalationransomwareremote code executionsupply-chain compromisetelnetd

What happened

A batch of high-impact security stories from The Hacker News highlights multiple active supply-chain and high-severity exploits: Trivy GitHub Actions packages were breached to steal CI/CD secrets; Langflow’s critical missing-auth/code-injection bug (CVE-2026-33017) was weaponized within 20 hours of disclosure; Interlock ransomware is exploiting a critical Cisco FMC deserialization zero-day (CVE-2026-20131) for root access; a GNU inetutils telnetd out-of-bounds write (CVE-2026-32746) allows unauthenticated root RCE; Ubuntu systemd cleanup timing bug enables local root escalation (CVE-2026-3888)

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
5232234c1ac9ecc1c81acb0c24ee2c1feb7672f10ced499629e8a988996f9f23
Enrichment time
2026-03-21T07:24:07Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.