| ▲ | Shank 14 hours ago | |
This attack seems predicated on a prior security incident (https://socket.dev/blog/unauthorized-ai-agent-execution-code...) at Trivy where they failed to successfully remediate and contain the damage. I think at this time, Trivy should’ve undertaken a full reassessment of risks and clearly isolated credentials and reduced risk systemically. This did not happen, and the second compromise occurred. | ||
| ▲ | NewJazz 12 hours ago | parent [-] | |
They did a lot of what you describe, although perhaps not well enough. | ||