The Trivy vulnerability scanner was compromised in a supply-chain attack by threat actors known as TeamPCP, which distributed ...
Because attacker-supplied flow data is used in public flows, the bug leads to unauthenticated remote code execution.