Open source is under attack with a new wave of supply chain attacks.
It has been a bad, bad few weeks for open-source security. It all started on March 19, 2026, when a severe supply chain attack on the Aqua Security Trivy vulnerability scanner occurred, as hackers, TeamPCP, compromised the project’s continuous integration and delivery (CI/CD) pipeline and GitHub repositories repeatedly. Once in, the attackers trojanized Trivy binaries and actions to steal sensitive credentials from CI/CD pipelines.
This was not a good look…

![[CITYPNG.COM]White Google Play PlayStore Logo – 1500×1500](https://startupnews.fyi/wp-content/uploads/2025/08/CITYPNG.COMWhite-Google-Play-PlayStore-Logo-1500x1500-1-630x630.png)