home.social

#aquasecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #aquasecurity, aggregated by home.social.

  1. Now sure how much #AquaSecurity has cost the software industry by not rotating their keys after already being exploited - but at the time of posting there is at least 188 people in an internal channel related to their repos being exposed, and that's just our part of IKEA. I'd estimate for us it's at least €150k-€200k just for today wasted because the entire software industry seems to treat security as 'something to be done' instead of at the heart of everything we do. #trivy #secOps

  2. Now sure how much #AquaSecurity has cost the software industry by not rotating their keys after already being exploited - but at the time of posting there is at least 188 people in an internal channel related to their repos being exposed, and that's just our part of IKEA. I'd estimate for us it's at least €150k-€200k just for today wasted because the entire software industry seems to treat security as 'something to be done' instead of at the heart of everything we do. #trivy #secOps

  3. Now sure how much #AquaSecurity has cost the software industry by not rotating their keys after already being exploited - but at the time of posting there is at least 188 people in an internal channel related to their repos being exposed, and that's just our part of IKEA. I'd estimate for us it's at least €150k-€200k just for today wasted because the entire software industry seems to treat security as 'something to be done' instead of at the heart of everything we do. #trivy #secOps

  4. Now sure how much #AquaSecurity has cost the software industry by not rotating their keys after already being exploited - but at the time of posting there is at least 188 people in an internal channel related to their repos being exposed, and that's just our part of IKEA. I'd estimate for us it's at least €150k-€200k just for today wasted because the entire software industry seems to treat security as 'something to be done' instead of at the heart of everything we do. #trivy #secOps

  5. Now sure how much #AquaSecurity has cost the software industry by not rotating their keys after already being exploited - but at the time of posting there is at least 188 people in an internal channel related to their repos being exposed, and that's just our part of IKEA. I'd estimate for us it's at least €150k-€200k just for today wasted because the entire software industry seems to treat security as 'something to be done' instead of at the heart of everything we do. #trivy #secOps

  6. 🚨 Oh no, not another "supply chain attack"! This time, our heroes, #TeamPCP, have turned Aqua Security's Trivy into a #malware vending machine. 🛒 But don't worry, folks, just a quick #audit will fix everything—because nothing says "secure" like a last-minute scramble. 😂🔒
    wiz.io/blog/trivy-compromised- #supplychainattack #security #AquaSecurity #HackerNews #ngated

  7. 🚨 Oh no, not another "supply chain attack"! This time, our heroes, #TeamPCP, have turned Aqua Security's Trivy into a #malware vending machine. 🛒 But don't worry, folks, just a quick #audit will fix everything—because nothing says "secure" like a last-minute scramble. 😂🔒
    wiz.io/blog/trivy-compromised- #supplychainattack #security #AquaSecurity #HackerNews #ngated

  8. 🚨 Oh no, not another "supply chain attack"! This time, our heroes, #TeamPCP, have turned Aqua Security's Trivy into a #malware vending machine. 🛒 But don't worry, folks, just a quick #audit will fix everything—because nothing says "secure" like a last-minute scramble. 😂🔒
    wiz.io/blog/trivy-compromised- #supplychainattack #security #AquaSecurity #HackerNews #ngated

  9. 🚨 Oh no, not another "supply chain attack"! This time, our heroes, #TeamPCP, have turned Aqua Security's Trivy into a #malware vending machine. 🛒 But don't worry, folks, just a quick #audit will fix everything—because nothing says "secure" like a last-minute scramble. 😂🔒
    wiz.io/blog/trivy-compromised- #supplychainattack #security #AquaSecurity #HackerNews #ngated

  10. 🚨 Oh no, not another "supply chain attack"! This time, our heroes, #TeamPCP, have turned Aqua Security's Trivy into a #malware vending machine. 🛒 But don't worry, folks, just a quick #audit will fix everything—because nothing says "secure" like a last-minute scramble. 😂🔒
    wiz.io/blog/trivy-compromised- #supplychainattack #security #AquaSecurity #HackerNews #ngated

  11. Hackers have compromised Trivy, a widely used open-source vulnerability scanner with 33,200 GitHub stars. The supply chain attack affected 75 trivy-action tags, allowing attackers to steal GitHub tokens, cloud credentials, SSH keys and Kubernetes tokens from developer pipelines. Users should rotate all secrets immediately. arstechnica.com/security/2026/ #AIagent #AI #GenAI #Security #AquaSecurity #Trivy

  12. Hackers have compromised Trivy, a widely used open-source vulnerability scanner with 33,200 GitHub stars. The supply chain attack affected 75 trivy-action tags, allowing attackers to steal GitHub tokens, cloud credentials, SSH keys and Kubernetes tokens from developer pipelines. Users should rotate all secrets immediately. arstechnica.com/security/2026/ #AIagent #AI #GenAI #Security #AquaSecurity #Trivy

  13. Hackers have compromised Trivy, a widely used open-source vulnerability scanner with 33,200 GitHub stars. The supply chain attack affected 75 trivy-action tags, allowing attackers to steal GitHub tokens, cloud credentials, SSH keys and Kubernetes tokens from developer pipelines. Users should rotate all secrets immediately. arstechnica.com/security/2026/ #AIagent #AI #GenAI #Security #AquaSecurity #Trivy

  14. Hackers have compromised Trivy, a widely used open-source vulnerability scanner with 33,200 GitHub stars. The supply chain attack affected 75 trivy-action tags, allowing attackers to steal GitHub tokens, cloud credentials, SSH keys and Kubernetes tokens from developer pipelines. Users should rotate all secrets immediately. arstechnica.com/security/2026/ #AIagent #AI #GenAI #Security #AquaSecurity #Trivy

  15. Hackers have compromised Trivy, a widely used open-source vulnerability scanner with 33,200 GitHub stars. The supply chain attack affected 75 trivy-action tags, allowing attackers to steal GitHub tokens, cloud credentials, SSH keys and Kubernetes tokens from developer pipelines. Users should rotate all secrets immediately. arstechnica.com/security/2026/ #AIagent #AI #GenAI #Security #AquaSecurity #Trivy

  16. Widely used #Trivy #scanner compromised in ongoing supply-chain #attack

    #Hackers have compromised virtually all versions of #AquaSecurity ’s widely used Trivy #vulnerability scanner in an ongoing #supplychain attack that could have wide-ranging consequences for #developers and the organizations that use them.

    Trivy maintainer Itay Shakury confirmed the compromise on Friday,
    #security #privacy

    arstechnica.com/security/2026/

  17. Widely used #Trivy #scanner compromised in ongoing supply-chain #attack

    #Hackers have compromised virtually all versions of #AquaSecurity ’s widely used Trivy #vulnerability scanner in an ongoing #supplychain attack that could have wide-ranging consequences for #developers and the organizations that use them.

    Trivy maintainer Itay Shakury confirmed the compromise on Friday,
    #security #privacy

    arstechnica.com/security/2026/

  18. Widely used #Trivy #scanner compromised in ongoing supply-chain #attack

    #Hackers have compromised virtually all versions of #AquaSecurity ’s widely used Trivy #vulnerability scanner in an ongoing #supplychain attack that could have wide-ranging consequences for #developers and the organizations that use them.

    Trivy maintainer Itay Shakury confirmed the compromise on Friday,
    #security #privacy

    arstechnica.com/security/2026/

  19. Widely used compromised in ongoing supply-chain

    have compromised virtually all versions of ’s widely used Trivy scanner in an ongoing attack that could have wide-ranging consequences for and the organizations that use them.

    Trivy maintainer Itay Shakury confirmed the compromise on Friday,

    arstechnica.com/security/2026/

  20. Widely used #Trivy #scanner compromised in ongoing supply-chain #attack

    #Hackers have compromised virtually all versions of #AquaSecurity ’s widely used Trivy #vulnerability scanner in an ongoing #supplychain attack that could have wide-ranging consequences for #developers and the organizations that use them.

    Trivy maintainer Itay Shakury confirmed the compromise on Friday,
    #security #privacy

    arstechnica.com/security/2026/