We wanted to provide you information about a security incident that we became aware of that affects customers who use the Aqua Security Vulnerability scanner (Trivy) across multiple distribution channels including Docker Hub, GitHub, and npm. Between 18:24 UTC on March 19, 2026 and 01:36 UTC on March 23, 2026, Docker Hub customers who pulled the Trivy images with the 0.69.4
, 0.69.5
, 0.69.6
, and...
The incident highlights the vulnerability of trust rooted in credentials rather than build systems, as a single stolen push token allowed the attacker to overwrite trusted image tags on a public registry. This underscores the importance of secure build environments and verified provenance attestations in preventing similar attacks. It is crucial for users to regularly check their repositories, including registry mirrors or artifact caches, for compromised images and to rotate sensitive data freq...
