Blogs

Trivy Under Attack Again: Widespread GitHub Actions Tag Compromise Exposes CI/CD Secrets

Socket

Attackers compromised Trivy GitHub Actions by force-updating tags to deliver malware, exposing CI/CD secrets across affected pipelines.

Visit Site

Blogs Socket

BlogsLarge-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation CampaignSocket BlogsRe-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-HuludSocket BlogsAnthropic Identifies Biased Reasoning and Recklessness as Drivers of Claude’s PyPI AttackSocket BlogsIntroducing Dependency Divergence GitHub ActionSocket BlogsUpdated and Ongoing Supply Chain Attack Targets CrowdStrike npm PackagesSocket BlogsTwitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot ServiceSocket BlogsLooping by Zapier: Repeat actions for itemsZapier NewsIntegrate Jupyter Notebooks with GitHubThenewstack NewsFlockport: Time to Start All Over Again and Return to LXC ContainersThenewstack BlogsPulumi ESC and External Secrets Operator: The Perfect Solution for TodayPulumi BlogsHow We Eliminated Long-Lived CI Secrets Across 70+ ReposPulumi BlogsPulumi Neo Now Supports AGENTS.mdPulumi BlogsPushing Pulumi ESC Secrets into External PlatformsPulumi ResourcesThe Go Memory Model - The Go Programming LanguageGo BlogsHow AI Assistants Can Decode GitHub Repos for UI WritersDocker LearnBuild Your Own PluginVercel ResourcesGitHub - MintlifyMintlify BlogsHow the AI Business World Actually Works: A Startup’s WarDeepgram LearnReal-Time Speech-to-Speech Translation: Architecture GuideDeepgram BlogsHow to instantly follow up on Facebook Lead Ads with custom notificationsZapier