all tags
Trivy’s March Supply Chain Attack Shows Where Secret Exposure Hurts Most

Trivy’s March Supply Chain Attack Shows Where Secret Exposure Hurts Most

The Trivy story is moving quickly, and the latest reporting makes one thing clear: this is no longer just a GitHub Actions tag hijack. What started as a compromise of trivy-action, setup-trivy, and the v0.69.4 release has expanded into malicious Docker Hub images.

Top 10 Non-Human Identity Security Tools and Platforms for 2026

Top 10 Non-Human Identity Security Tools and Platforms for 2026

Non-human identities outnumber humans 10:1 in cloud-native orgs. Top risks: unmanaged lifecycles, overprivileged access, and exposed credentials. The best NHI security tools in 2026 span secrets detection, lifecycle governance, machine identity management, and vault extensions for layered coverage.

Start your journey to secrets-free source code

And keep your secrets out of sight