home.social

#aquasecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #aquasecurity, aggregated by home.social.

fetched live
  1. Now sure how much #AquaSecurity has cost the software industry by not rotating their keys after already being exploited - but at the time of posting there is at least 188 people in an internal channel related to their repos being exposed, and that's just our part of IKEA. I'd estimate for us it's at least €150k-€200k just for today wasted because the entire software industry seems to treat security as 'something to be done' instead of at the heart of everything we do. #trivy #secOps

  2. Now sure how much #AquaSecurity has cost the software industry by not rotating their keys after already being exploited - but at the time of posting there is at least 188 people in an internal channel related to their repos being exposed, and that's just our part of IKEA. I'd estimate for us it's at least €150k-€200k just for today wasted because the entire software industry seems to treat security as 'something to be done' instead of at the heart of everything we do. #trivy #secOps

  3. Now sure how much #AquaSecurity has cost the software industry by not rotating their keys after already being exploited - but at the time of posting there is at least 188 people in an internal channel related to their repos being exposed, and that's just our part of IKEA. I'd estimate for us it's at least €150k-€200k just for today wasted because the entire software industry seems to treat security as 'something to be done' instead of at the heart of everything we do. #trivy #secOps

  4. Now sure how much #AquaSecurity has cost the software industry by not rotating their keys after already being exploited - but at the time of posting there is at least 188 people in an internal channel related to their repos being exposed, and that's just our part of IKEA. I'd estimate for us it's at least €150k-€200k just for today wasted because the entire software industry seems to treat security as 'something to be done' instead of at the heart of everything we do. #trivy #secOps

  5. 🚨 Oh no, not another "supply chain attack"! This time, our heroes, #TeamPCP, have turned Aqua Security's Trivy into a #malware vending machine. 🛒 But don't worry, folks, just a quick #audit will fix everything—because nothing says "secure" like a last-minute scramble. 😂🔒
    wiz.io/blog/trivy-compromised- #supplychainattack #security #AquaSecurity #HackerNews #ngated

  6. 🚨 Oh no, not another "supply chain attack"! This time, our heroes, #TeamPCP, have turned Aqua Security's Trivy into a #malware vending machine. 🛒 But don't worry, folks, just a quick #audit will fix everything—because nothing says "secure" like a last-minute scramble. 😂🔒
    wiz.io/blog/trivy-compromised- #supplychainattack #security #AquaSecurity #HackerNews #ngated

  7. 🚨 Oh no, not another "supply chain attack"! This time, our heroes, #TeamPCP, have turned Aqua Security's Trivy into a #malware vending machine. 🛒 But don't worry, folks, just a quick #audit will fix everything—because nothing says "secure" like a last-minute scramble. 😂🔒
    wiz.io/blog/trivy-compromised- #supplychainattack #security #AquaSecurity #HackerNews #ngated

  8. 🚨 Oh no, not another "supply chain attack"! This time, our heroes, #TeamPCP, have turned Aqua Security's Trivy into a #malware vending machine. 🛒 But don't worry, folks, just a quick #audit will fix everything—because nothing says "secure" like a last-minute scramble. 😂🔒
    wiz.io/blog/trivy-compromised- #supplychainattack #security #AquaSecurity #HackerNews #ngated

  9. Hackers have compromised Trivy, a widely used open-source vulnerability scanner with 33,200 GitHub stars. The supply chain attack affected 75 trivy-action tags, allowing attackers to steal GitHub tokens, cloud credentials, SSH keys and Kubernetes tokens from developer pipelines. Users should rotate all secrets immediately. arstechnica.com/security/2026/ #AIagent #AI #GenAI #Security #AquaSecurity #Trivy

  10. Hackers have compromised Trivy, a widely used open-source vulnerability scanner with 33,200 GitHub stars. The supply chain attack affected 75 trivy-action tags, allowing attackers to steal GitHub tokens, cloud credentials, SSH keys and Kubernetes tokens from developer pipelines. Users should rotate all secrets immediately. arstechnica.com/security/2026/ #AIagent #AI #GenAI #Security #AquaSecurity #Trivy

  11. Hackers have compromised Trivy, a widely used open-source vulnerability scanner with 33,200 GitHub stars. The supply chain attack affected 75 trivy-action tags, allowing attackers to steal GitHub tokens, cloud credentials, SSH keys and Kubernetes tokens from developer pipelines. Users should rotate all secrets immediately. arstechnica.com/security/2026/ #AIagent #AI #GenAI #Security #AquaSecurity #Trivy

  12. Hackers have compromised Trivy, a widely used open-source vulnerability scanner with 33,200 GitHub stars. The supply chain attack affected 75 trivy-action tags, allowing attackers to steal GitHub tokens, cloud credentials, SSH keys and Kubernetes tokens from developer pipelines. Users should rotate all secrets immediately. arstechnica.com/security/2026/ #AIagent #AI #GenAI #Security #AquaSecurity #Trivy

  13. Widely used #Trivy #scanner compromised in ongoing supply-chain #attack

    #Hackers have compromised virtually all versions of #AquaSecurity ’s widely used Trivy #vulnerability scanner in an ongoing #supplychain attack that could have wide-ranging consequences for #developers and the organizations that use them.

    Trivy maintainer Itay Shakury confirmed the compromise on Friday,
    #security #privacy

    arstechnica.com/security/2026/

  14. Widely used #Trivy #scanner compromised in ongoing supply-chain #attack

    #Hackers have compromised virtually all versions of #AquaSecurity ’s widely used Trivy #vulnerability scanner in an ongoing #supplychain attack that could have wide-ranging consequences for #developers and the organizations that use them.

    Trivy maintainer Itay Shakury confirmed the compromise on Friday,
    #security #privacy

    arstechnica.com/security/2026/

  15. Widely used compromised in ongoing supply-chain

    have compromised virtually all versions of ’s widely used Trivy scanner in an ongoing attack that could have wide-ranging consequences for and the organizations that use them.

    Trivy maintainer Itay Shakury confirmed the compromise on Friday,

    arstechnica.com/security/2026/

  16. Widely used #Trivy #scanner compromised in ongoing supply-chain #attack

    #Hackers have compromised virtually all versions of #AquaSecurity ’s widely used Trivy #vulnerability scanner in an ongoing #supplychain attack that could have wide-ranging consequences for #developers and the organizations that use them.

    Trivy maintainer Itay Shakury confirmed the compromise on Friday,
    #security #privacy

    arstechnica.com/security/2026/

  17. "🔒 Redis Threat Alert: HeadCrab 2.0 Unleashed 🔒"

    The latest analysis by Aqua Security unveils HeadCrab 2.0, targeting Redis servers with advanced evasion techniques. HeadCrab 2.0 is an evolved malware targeting Redis servers, significantly more sophisticated than its predecessor. This malware employs a fileless loader mechanism to evade detection, making it harder to spot by hiding its presence on the system. It also uses standard Redis commands for malicious activities, further concealing its operations. Aqua Security researchers have identified a method to detect this malware by scanning for abnormal responses from the infected servers. This discovery can be crucial for cybersecurity efforts and detection. Stay secure! 🛡️

    Tags: #CyberSecurity #Redis #Malware #HeadCrab2.0 #InfoSec #AquaSecurity

    For an in-depth look, check out Aqua Security's blog.

  18. "🔒 Redis Threat Alert: HeadCrab 2.0 Unleashed 🔒"

    The latest analysis by Aqua Security unveils HeadCrab 2.0, targeting Redis servers with advanced evasion techniques. HeadCrab 2.0 is an evolved malware targeting Redis servers, significantly more sophisticated than its predecessor. This malware employs a fileless loader mechanism to evade detection, making it harder to spot by hiding its presence on the system. It also uses standard Redis commands for malicious activities, further concealing its operations. Aqua Security researchers have identified a method to detect this malware by scanning for abnormal responses from the infected servers. This discovery can be crucial for cybersecurity efforts and detection. Stay secure! 🛡️

    Tags: #CyberSecurity #Redis #Malware #HeadCrab2.0 #InfoSec #AquaSecurity

    For an in-depth look, check out Aqua Security's blog.

  19. "🔒 Redis Threat Alert: HeadCrab 2.0 Unleashed 🔒"

    The latest analysis by Aqua Security unveils HeadCrab 2.0, targeting Redis servers with advanced evasion techniques. HeadCrab 2.0 is an evolved malware targeting Redis servers, significantly more sophisticated than its predecessor. This malware employs a fileless loader mechanism to evade detection, making it harder to spot by hiding its presence on the system. It also uses standard Redis commands for malicious activities, further concealing its operations. Aqua Security researchers have identified a method to detect this malware by scanning for abnormal responses from the infected servers. This discovery can be crucial for cybersecurity efforts and detection. Stay secure! 🛡️

    Tags: #CyberSecurity #Redis #Malware #HeadCrab2.0 #InfoSec #AquaSecurity

    For an in-depth look, check out Aqua Security's blog.