Security Advisories
This page tracks security vulnerabilities that affect AccuKnox products and the third-party components we depend on. We disclose in accordance with coordinated responsible disclosure principles.
Report a VulnerabilitySeverity
Status

May 25, 2026
Trivy Supply Chain Compromise - Credential Exfiltration via Malicious GitHub Actions
Threat actor group TeamPCP injected credential-stealing malware into Trivy vO.69.4 and vO.69.5, and force-pushed to trivy-action and setup-trivy. AccuKnox infrastructure is not directly vulnerable. Credential rotation recommended.
Download PDF

