Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets

2026-03-21T01:24:15Ze122b2e0f460a8180bf64afa36999deaf28d18110a0b884236ca100d13a77a59
active-exploitationandroid-malwarebyovdci/cd-secretscisco-fmcdarkswordedr-bypassgithub-actionsinterlockiot-botnetslangflowleaknetmagentoperseuspolyshellransomwarespeaglesupply-chaintelnetdtrivyubuntu-systemdweb-applicationwebkitzero-dayzimbra

What happened

Multiple high-impact incidents and active exploits were reported across open-source supply chain components, enterprise appliances, and endpoint/mobile malware. Key developments: the Trivy GitHub Actions packages were compromised to exfiltrate CI/CD secrets via hijacked tags; Langflow’s critical missing-authentication/code-injection flaw (CVE-2026-33017, CVSS 9.3) was weaponized within ~20 hours of disclosure; Interlock ransomware is actively exploiting a Cisco FMC insecure-deserialization zero-day (CVE-2026-20131, CVSS 10.0) for root access. Additional critical vulnerabilities disclosed or in

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
e122b2e0f460a8180bf64afa36999deaf28d18110a0b884236ca100d13a77a59
Enrichment time
2026-03-21T01:24:15Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets · Baitaphish