← Back to feed
research Trail of Bits

Bringing full YAML anchor support to zizmor

Trail of Bits GitHub

In March 2026, attackers exploited a pull_request_target misconfiguration in the aquasecurity/trivy-action GitHub Action to exfiltrate organization and repos...

T1041
Read the full story Trail of Bits →

Related Coverage

research Network Anomaly Detection in KATA Kaspersky Securelist · Jul 31 research The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version Unit 42 · Jul 31 research Exploring the Hugging Face Breach: mapping AI agent tactics to Elastic Defend Elastic Security Labs · Jul 31