← Back to feed
research Trail of Bits

Bringing full YAML anchor support to zizmor

Trail of Bits GitHub

In March 2026, attackers exploited a pull_request_target misconfiguration in the aquasecurity/trivy-action GitHub Action to exfiltrate organization and repos...

T1041
Read the full story Trail of Bits →

Related Coverage

research 24th August – Threat Intelligence Report Check Point Research · Aug 24 research How a team of entity maintainers monitors, connects and scores entities in Elastic Security Elastic Security Labs · Aug 24 research Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain Unit 42 · Aug 21