Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets
2026-03-21T01:24:15Z•e122b2e0f460a8180bf64afa36999deaf28d18110a0b884236ca100d13a77a59
active-exploitationandroid-malwarebyovdci/cd-secretscisco-fmcdarkswordedr-bypassgithub-actionsinterlockiot-botnetslangflowleaknetmagentoperseuspolyshellransomwarespeaglesupply-chaintelnetdtrivyubuntu-systemdweb-applicationwebkitzero-dayzimbra
What happened
Multiple high-impact incidents and active exploits were reported across open-source supply chain components, enterprise appliances, and endpoint/mobile malware. Key developments: the Trivy GitHub Actions packages were compromised to exfiltrate CI/CD secrets via hijacked tags; Langflow’s critical missing-authentication/code-injection flaw (CVE-2026-33017, CVSS 9.3) was weaponized within ~20 hours of disclosure; Interlock ransomware is actively exploiting a Cisco FMC insecure-deserialization zero-day (CVE-2026-20131, CVSS 10.0) for root access. Additional critical vulnerabilities disclosed or in
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- e122b2e0f460a8180bf64afa36999deaf28d18110a0b884236ca100d13a77a59
- Enrichment time
- 2026-03-21T01:24:15Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.