Security

Trivy Supply‑Chain Compromise / CloudSEK Disclosure

 

Updated: August 24, 2026:

Barracuda obtained additional information in August from CloudSEK and identified an additional secret that had not been rotated. We rotated the secret and conducted a full review of available logs. We have found no evidence of unauthorized access or use of any of our secrets, and we have now concluded our investigation.

Summary

Aqua Security disclosed a compromise of its Trivy security scanning tool in March 2026, in which attackers used stolen credentials to publish malicious binaries, container images and GitHub Action tags. On August 12, 2026, CloudSEK published a public lookup of thousands of potentially impacted organizations. 

There is no evidence of any impact to Barracuda systems or customer environments. Following Aqua Security's disclosure in March 2026, Barracuda immediately implemented proactive mitigation measures, including credential rotation and enhanced monitoring, to protect its systems and customers. 

Barracuda continues to monitor the situation closely and has identified no evidence of any related impact. It will update this advisory if new information becomes available.

Incident Description 

The compromise, believed to have been carried out by threat actor group TeamPCP, affected Trivy v0.69.4 and several related container images and GitHub Action tags. Malicious versions were briefly available across GitHub and Docker Hub before being removed. Any organization that executed affected versions during the exposure window may have been listed in public disclosures.

Affected components: 

  • Trivy binary v0.69.4
  • Trivy container images v0.69.4–0.69.6
  • GitHub Actions:
    • aquasecurity/trivy-action versions 0.0.1–0.34.2
    • aquasecurity/setup-trivy versions 0.2.0–0.2.6

Safe versions include Trivy v0.69.2, v0.69.3, trivy-action 0.35.0, and setup-trivy 0.2.6. 

Recommended Actions

Organizations using Trivy should:

  • Check whether affected versions were executed.
  • Review CI/CD workflows for compromised GitHub Action tags.
  • Rotate any secrets accessible to pipelines that used impacted versions.
  • Pin GitHub Actions to immutable commit SHAs.