Вход на сайт

Просмотр новости

Найдите то, что Вас интересует

Reminder: Rotate credentials if you use Trivy in your CI/CD pipelines

Дата публикации: 20-03-2026 15:48:09


This notice is not related to the CircleCI product. We are sharing this as a courtesy to help our customers avoid compromise and follow security best practices.
We’ve been made aware of an ongoing compromise affecting Trivy, the popular open-source vulnerability scanner. On March 19, 2026, a malicious release (v0.69.4) was published to the Trivy Github repository. Binaries from this release contained credential-exfiltration malware - code that phones home to an attacker-controlled domain. The compromised release has since been removed by Trivy maintainers.
Additional information can be found in this write-up from StepSecurity:


stepsecurity.io



Trivy Compromised a Second Time - Malicious v0.69.4 Release,...
On March 19, 2026, trivy — a widely used open source vulnerability scanner maintained by Aqua Security — experienced a second security incident. Three weeks after the hackerbot-claw incident on February 28 that resulted in a repository takeover, a...






What we observed
While assisting a customer with their investigation into suspicious activity, we identified a case where a compromised Trivy v0.69.4 binary was fetched and executed during a CI build. The malicious binary exfiltrated a temporary OIDC-based AWS credential pair from the build environment, which was then used by an unauthorized party to access AWS resources.
What this means for you
If your CI/CD pipelines use Trivy at build time (e.g. from Github releases, Homebrew, or Dockerhub), and any build ran between approximately 17:43 UTC and 23:13 UTC on March 19, 2026, you may have executed the compromised binary. Any secret or token accessible in that build environment should be considered potentially exposed.
Recommended actions
Rotate all tokens, credentials, and secrets that were present in any build environment where Trivy 0.69.4 may have been installed or running. This includes CI/CD tokens, cloud provider credentials, and any secrets injected via contexts or environment variables.
Pin your Trivy installation to a verified version (v0.69.3 or a forthcoming patched release) and validate the binary checksum before execution.
Look out for malicious activities in all audit logs; review your cloud audit logs (e.g AWS CloudTrail) for any unexpected activity from roles or credentials used in your CI pipelines
Review our guide on token rotation best practices: https://support.circleci.com/hc/en-us/articles/11858740696219-Best-Practices-of-API-Token-Rotation
If you have further questions, please work with the Technical Success Manager from your account team, or visit support.circleci.com for more guides.
1 post - 1 participant
Read full topic


Основное содержимое страницы с новостью.

<------>

Схожие новости

#Наименование новостиТональностьИнформативностьДата публикации
1Reminder: Rotate credentials if you use LiteLLM in your CI/CD pipelines010.3824-03-2026
2Security notice: Beware of spear phishing07.8806-10-2026
3Security advisory: Secrets in builds from forked pull requests05.602-05-2026
4GitHub Webhook Secret Exposure — Action Required for GitHub OAuth Projects011.6514-04-2026
5CircleCI response to CVE-2026-31431 ("Copy Fail" Linux kernel vulnerability)06.7902-05-2026
6PocketCI - CircleCI in your pocket08.7929-09-2026
7Fix failing workflows with Claude Code, directly from the CircleCI UI015.9406-08-2026
8OAuth 2.0 API Access with Dynamic Client Registration09.6812-08-2026
9CircleCI Response to CVE-2026-64600 ("RefluXFS") Linux Kernel Vulnerability09.3829-07-2026

Классификация: . Схожих патентов: 0. Схожих новостей: 9. Тональность: 0. Информативность: 11.04. Источник: discuss.circleci.com.