Trivy Supply Chain Attack: Security Scanner Turned Credential Stealer in GitHub Actions Compromise
TeamPCP hijacked 75 of 76 version tags in Trivy's GitHub Actions, turning the popular vulnerability scanner into a sophisticated credential harvesting operation.