<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>WildforTech Security Advisories — Aquasecurity</title><description>Actively exploited vulnerabilities affecting Aquasecurity products.</description><link>https://wildfortech.com</link><atom:link href="https://wildfortech.com/security/vendor/aquasecurity.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-33634 — Aquasecurity Trivy Embedded Malicious Code Vulnerability</title><link>https://wildfortech.com/security#CVE-2026-33634</link><guid isPermaLink="true">https://wildfortech.com/security#CVE-2026-33634</guid><description>Trivy, a widely used open-source vulnerability scanner commonly embedded in CI/CD pipelines, has been found to contain malicious code. Because Trivy runs with access to pipeline environments, an attacker exploiting this could harvest every secret the pipeline touches — OAuth tokens, SSH keys, cloud provider credentials, database passwords, and sensitive in-memory configuration. Any organization using Trivy in automated build or deployment workflows should treat this as a high-priority supply chain compromise.</description><pubDate>Thu, 26 Mar 2026 00:00:00 GMT</pubDate><category>Aquasecurity</category><category>Trivy</category></item></channel></rss>