Aqua Security’s GitHub org was briefly taken over during the Trivy incident. Archived snapshots show attacker-created repos (e.g. tpcp-docs-*) with messages like “TeamPCP Owns Aqua Security,” indicating the attacker had write access to the org. Our post has been updated with more details:
1 likes 0 replies
?