Over 10 years we help companies reach their financial and branding goals. Engitech is a values-driven technology agency dedicated.

Gallery

Contacts

411 University St, Seattle, USA

engitech@oceanthemes.net

+1 -800-456-478-23

Attackers compromised Aqua Security’s GitHub Actions infrastructure for the Trivy vulnerability scanner and KICS static analysis tool, hijacking approximately 75 release tags and injecting malicious code into CI/CD workflows. After Aqua’s initial containment, the threat actor re-established access and published a second malicious release (v0.69.4), confirming persistence beyond the initial intrusion. Any organization running Trivy GitHub Actions, trivy-action, setup-trivy, or KICS GitHub Action in their pipelines is at risk of executing attacker-controlled code during their software build and deployment processes.

Author

Tech Jacks Solutions