Security Daily Digest
?
← BACK TO TODAY

Cybersecurity news, daily.

2026.03.22

18 sources scanned
FEATURED
01

Trivy Vulnerability Scanner Compromised in Supply Chain Attack

The Trivy vulnerability scanner was compromised in a supply chain attack, with threat actors deploying an infostealer via GitHub Actions. The attack involved the Trivy scanner being used to spread CanisterWorm across 47 npm packages. This incident highlights the risks associated with software supply chains and the need for rigorous security measures around CI/CD pipelines and third-party tool integrations.

SRC BleepingComputerThe Hacker News
02

Oracle Releases Patch for Critical RCE Flaw in Identity Manager

Oracle has issued a patch for a critical remote code execution vulnerability (CVE-2026-21992) in its Identity Manager, which could be exploited by unauthenticated attackers. Meanwhile, CISA has flagged this and other vulnerabilities in Apple, Craft CMS, and Laravel, mandating patching by April 3, 2026. Security teams should prioritize applying these updates to mitigate potential exploitation risks.

SRC The Hacker News
SIGNAL

STAY UPDATED

Daily security digest, straight to your inbox.

ARCHIVE