Saturday, 4 Apr 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Global Market > CERT-EU blames Trivy supply chain attack for Europa.eu data breach
Global Market

CERT-EU blames Trivy supply chain attack for Europa.eu data breach

Last updated: April 4, 2026 12:04 am
Published April 4, 2026
Share
The European Commission headquarters in Brussels (8)
SHARE

Again door credentials

The Trivy compromise dates to February, when TeamPCP exploited a misconfiguration in Trivy’s GitHub Actions setting, now recognized as CVE-2026-33634, to ascertain a foothold by way of a privileged entry token, according to Aqua Security.

Discovering this, Aqua Safety rotated credentials however, as a result of some credentials stay legitimate throughout this course of, the attackers had been capable of steal the newly rotated credentials.

By manipulating trusted Trivy model tags, TeamPCP compelled CI/CD pipelines utilizing the software to robotically pull down credential-stealing malware it had implanted.

This allowed TeamPCP to focus on quite a lot of beneficial info together with AWS, GCP, Azure cloud credentials, Kubernetes tokens, Docker registry credentials, database passwords, TLS personal keys, SSH keys, and cryptocurrency pockets information, based on safety researchers at Palo Alto Networks. In impact, the attackers had turned a software used to search out cloud vulnerabilities and misconfigurations right into a yawning vulnerability of its personal.

CERT-EU suggested organizations affected by the Trivy compromise to right away replace to a recognized protected model, rotate all AWS and different credentials, audit Trivy variations in CI/CD pipelines, and most significantly guarantee GitHub Actions are tied to immutable SHA-1 hashes slightly than mutable tags.

It additionally really helpful in search of indicators of compromise (IoCs) corresponding to uncommon Cloudflare tunnelling exercise or visitors spikes which may point out information exfiltration.

Source link

See also  Cisco goes all in on agentic AI security
TAGGED: attack, blames, breach, CERTEU, chain, data, Europa.eu, Supply, Trivy
Share This Article
Twitter Email Copy Link Print
Previous Article Atos BullSequana XH3000 French government take Bull by horns for €404 million
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

Lanarkshire becomes Scotland’s first AI Growth Zone

Lanarkshire has been named the UK’s newest AI Progress Zone, with the UK Authorities backing…

January 31, 2026

UK secures £6.3bn investment in critical data centres

4 main US tech companies have dedicated to investing in UK information centres, fuelling Britain’s…

October 16, 2024

Red Hat launches advanced OpenShift AI platform for hybrid cloud environments

Pink Hat, a supplier of open supply options, unveiled developments in its Pink Hat OpenShift…

May 16, 2024

Darwin Raises $5M in Seed Funding

Darwin, a NYC-based firm which makes a speciality of AI safety and governance for the…

March 14, 2025

Tech leaders respond to the rapid rise of DeepSeek

Be a part of our each day and weekly newsletters for the newest updates and…

January 25, 2025

You Might Also Like

Atos BullSequana XH3000
Global Market

French government take Bull by horns for €404 million

By saad
Autonomous AI systems depend on data governance
AI

Autonomous AI systems depend on data governance

By saad
Artificial Intelligence Internet of Things Network Protection Global Business Robots Touch Key Protection Icons Digital technology concepts online marketing, data analysis, e-commerce connectivity
Global Market

Kyndryl service targets AI agent automation, security

By saad
Cisco building exterior with sign
Global Market

Cisco fixes critical IMC auth bypass present in many products

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.