Saturday, 25 Apr 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Global Market > CERT-EU blames Trivy supply chain attack for Europa.eu data breach
Global Market

CERT-EU blames Trivy supply chain attack for Europa.eu data breach

Last updated: April 4, 2026 12:04 am
Published April 4, 2026
Share
The European Commission headquarters in Brussels (8)
SHARE

Again door credentials

The Trivy compromise dates to February, when TeamPCP exploited a misconfiguration in Trivy’s GitHub Actions setting, now recognized as CVE-2026-33634, to ascertain a foothold by way of a privileged entry token, according to Aqua Security.

Discovering this, Aqua Safety rotated credentials however, as a result of some credentials stay legitimate throughout this course of, the attackers had been capable of steal the newly rotated credentials.

By manipulating trusted Trivy model tags, TeamPCP compelled CI/CD pipelines utilizing the software to robotically pull down credential-stealing malware it had implanted.

This allowed TeamPCP to focus on quite a lot of beneficial info together with AWS, GCP, Azure cloud credentials, Kubernetes tokens, Docker registry credentials, database passwords, TLS personal keys, SSH keys, and cryptocurrency pockets information, based on safety researchers at Palo Alto Networks. In impact, the attackers had turned a software used to search out cloud vulnerabilities and misconfigurations right into a yawning vulnerability of its personal.

CERT-EU suggested organizations affected by the Trivy compromise to right away replace to a recognized protected model, rotate all AWS and different credentials, audit Trivy variations in CI/CD pipelines, and most significantly guarantee GitHub Actions are tied to immutable SHA-1 hashes slightly than mutable tags.

It additionally really helpful in search of indicators of compromise (IoCs) corresponding to uncommon Cloudflare tunnelling exercise or visitors spikes which may point out information exfiltration.

Source link

See also  How Utilities, Hyperscalers Are Working to Tackle ‘Extreme’ Data Center Power Demands
TAGGED: attack, blames, breach, CERTEU, chain, data, Europa.eu, Supply, Trivy
Share This Article
Twitter Email Copy Link Print
Previous Article Atos BullSequana XH3000 French government take Bull by horns for €404 million
Next Article DCD Connect 2022 and Capacity Europe DCD Connect 2022 and Capacity Europe
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

Snowflake acquires TruEra to deliver LLM observability inside data cloud 

Be part of us in returning to NYC on June fifth to collaborate with govt…

May 28, 2024

New design demonstrates end-to-end energy-efficient cooling and power

Along with totally built-in end-to-end cooling and energy methods for this subsequent era platform, the…

June 13, 2025

Siemens Acquires DownStream Technologies

Siemens Digital Industries Software acquired DownStream Applied sciences, a Marlborough, MA-based supplier of producing options. The…

April 9, 2025

Pika 1.5 launches with physics-defying AI special effects

Be part of our day by day and weekly newsletters for the newest updates and…

October 2, 2024

Why Are Companies Moving to the Cloud?

In case you are questioning should you ought to migrate to the cloud and are…

September 23, 2024

You Might Also Like

kommunikatioin
Global Market

Space data-center news: Roundup of extraterrestrial AI endeavors

By saad
Meta logo seen on smartphone and AI letters on the background. Concept for Meta Facebook Artificial Intelligence. Stafford, UK, May 2, 2023
Global Market

Meta’s compute grab continues with agreement to deploy tens of millions of AWS Graviton cores

By saad
Aon expands Data Center Lifecycle Insurance Program
Colocation

Aon expands Data Center Lifecycle Insurance Program

By saad
italy-data-center-man-woman-it-specialist-mainframe
Global Market

Cirrascale to offer on-prem Google Gemini models

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.