Skip to content

project

Trivy

Trivy is an open-source scanner from Aqua Security that detects vulnerabilities and misconfigurations in container images, filesystems, and code repositories.

Known aliases

  • aquasecurity/trivy
  • setup-trivy
  • trivvy
  • trivy-action
  • Trivy campaign
  • Trivy GitHub Action
  • trivy operator
  • Trivy Supply Chain Attack

Relationships

No evidence-backed relationships are recorded.

Current stories

security17 publishers

AFP sizes the Shai-Hulud syndicate's take at more than 500,000 credentials

Two men arrested in Australia this week are alleged TeamPCP members. The AFP estimate filed alongside the case puts the worm's take at more than 500,000 credentials and 300GB of data, and that scale makes token lifetime the live question.

Perspective Coverage

17 publishers
Builder
Builder 33%
Operator
Operator 50%
Investor
Investor 17%

Reality

Evidence68
Adoption
Insufficient
Hype gap+25
Incentives55
Confidence62

Earlier coverage

  1. Oligo dates the crew behind ShadowRay 2.0's self-propagating botnet back to 2020

    Security · August 28, 2026 · 1 publisher

  2. 56 build-pipeline attacks, one vendor's alert queue, and the February jump nobody can attribute yet

    Build · August 23, 2026 · 1 publisher

  3. Reading OIDC tokens out of runner memory: ChainDrop and the poisoned build

    Security · August 21, 2026 · 1 publisher

  4. Flux moves GitOps' source of truth into registries you own, and mirroring becomes the prerequisite

    Build · August 20, 2026 · 1 publisher

  5. LiteLLM 1.82.7 and 1.82.8 shipped an infostealer: rotate everything those machines touched

    Science · August 20, 2026 · 1 publisher

  6. VECT 2.0 shreds anything over 128 KB, which makes paying its ransom pointless

    Leadership · August 18, 2026 · 1 publisher

  7. One alert, two causes, four green dashboards: the day the stack agreed and was wrong

    Build · August 18, 2026 · 1 publisher

  8. Docker pipes every agent policy decision into your SIEM, and the evidence burden lands on platform teams

    Product · August 17, 2026 · 1 publisher

  9. The 2,500-org compromise was a Trivy problem. LiteLLM was the closing act.

    Security · August 14, 2026 · 1 publisher