Remix.run Logo
Shank 14 hours ago

This attack seems predicated on a prior security incident (https://socket.dev/blog/unauthorized-ai-agent-execution-code...) at Trivy where they failed to successfully remediate and contain the damage. I think at this time, Trivy should’ve undertaken a full reassessment of risks and clearly isolated credentials and reduced risk systemically. This did not happen, and the second compromise occurred.

NewJazz 12 hours ago | parent [-]

They did a lot of what you describe, although perhaps not well enough.