← Back to feed
research Trail of Bits

Bringing full YAML anchor support to zizmor

Trail of Bits GitHub

In March 2026, attackers exploited a pull_request_target misconfiguration in the aquasecurity/trivy-action GitHub Action to exfiltrate organization and repos...

T1041
Read the full story Trail of Bits →

Related Coverage

research HTTP/3 in Burp Suite - it’s time to find a bigger wordlist PortSwigger Research · Sep 23 research The Lure Isn't The Malware. It's Your Logo. Recorded Future · Sep 23 research Looking for free Robux? Here’s what’s real, and what’s a scam ESET Research · Sep 22