A widespread vulnerability in the popular container‑scanning tool has been exploited, allowing attackers to inject malicious code into software packages. The incident, reported by Ars Technica Tech, highlights a growing trend of supply‑chain attacks targeting security tools.
The Signal
Trivy users are urged to rotate secrets, update dependencies, and monitor for unusual activity.