Sev0AI security incidents, tracked

All incidents / AI-run attack

Autonomous Claude-powered bot compromised the Trivy security scanner

Aqua Security (Trivy), disclosed Mar 2026. AI-run attack Exposed and destroyed High

A bot describing itself as an autonomous security research agent exploited a GitHub Actions misconfiguration in Trivy, stole a token, deleted releases and pushed a malicious VS Code extension. Incomplete credential rotation let a second group return weeks later and poison Trivy's actions, which led to the LiteLLM compromise.

Disclosed
Mar 2026
Organization
Aqua Security (Trivy)
Vendor
Anthropic
Model
Claude Opus 4.5
Product
hackerbot-claw
Type of AI
AI agent
How it happened
AI-run attack: Autonomous intrusion
Harm
Exposed and destroyed
Data involved
Credentials, Source code
Reach
Many organizations
Severity
High
Model at fault
Unclear
Status
Confirmed
Vulnerability IDs
CVE-2026-28353

Sources

  1. https://orca.security/resources/blog/hackerbot-claw-github-actions-attack/
  2. https://www.wiz.io/blog/trivy-compromised-teampcp-supply-chain-attack

Related incidents

Data for this record: incidents.json. Cite as: Sev0, "Autonomous Claude-powered bot compromised the Trivy security scanner", https://sev0.fyi/incidents/2026-03-01-trivy-hackerbot-claw/