Trivy GitHub Action compromise exposed CI/CD secrets in a stealth supply-chain attack A supply-chain compromise in Aqua Security’s aquasecurity/trivy-action sho...
Lucas Oliveira
Research
GlassWorm Shifts to Transitive Open VSX Dependencies in Developer Supply-Chain Push GlassWorm is no longer just a story about obviously malicious extensions. Th...
Lucas Oliveira
Research
FakeGit: GitHub malware campaign hits 600+ repos | 2026 Executive Summary A Vietnamese-speaking threat actor has been distributing FakeGit, a GitHub-based malwa...
Lucas Oliveira
Research