piyokango[verified]@piyokangoActive Exploitation
CVE‑2026‑33634, an Aqua Trivy vulnerability, was actively exploited in supply‑chain attacks that injected malicious code into official releases; the incident was confirmed by CISA and no mitigation is mentioned.
Virendra Patel[verified]@V1rendra_Disclosure
This post announces the exploitation of Trivy CVE-2026-33634 via supply‑chain attacks and urges users to audit and patch dependencies, but does not provide technical details, patches, or exploit code.
Ross Lazer[verified]@rosslazerGeneral
The post lists recent supply‑chain vulnerability findings, including a CVE‑2026‑33634 in Trivy, and urges organizations to audit their software dependencies and sub‑dependencies.
Krishna Kumar[verified]@krishnapro_Disclosure
The post announces a triple vulnerability disclosure (CVE-2026-33634) affecting LangChain, LangGraph, and LiteLLM, urging teams building AI-native backends to audit their serialization logic.
SOCRadar®[verified]@socradarActive Exploitation
CVE-2026-33634 has been added to the CISA Known Exploited Vulnerabilities list, indicating it is actively exploited in the wild, while the notice contains no PoC, exploit code, patch information, or technical details.
AgentCost In[verified]@agentcostinGeneral
The statement notes that AgentCost was unaffected by a published supply chain attack involving CVE-2026-33634, with no additional technical or mitigation details provided.
The Cyber Security Hub™[verified]@TheCyberSecHubActive Exploitation
CISA issues an alarm that CVE‑2026‑33017 (Langflow RCE) and CVE‑2026‑33634 (Trivy supply chain) are actively exploited, highlighting urgent vendor action.
GoCocoaAI[verified]@GoCocoaAIActive Exploitation
The passage highlights multiple CVEs, most notably a SharePoint RCE that has been confirmed as actively exploited by CISA, while also citing other vulnerabilities discussed in research notes without indicating available patches or exploit tools.