Skip to content
How Did Aqua Catch a Cryptomining Attack Hiding in Memory?
Sign in
Contact
Support
We're hiring!
Platform
Aqua Platform
Runtime Powered Cloud Security
Monitor behavior, detect exploitable risk, enforce policy and contain threats across the application lifecycle.
Platform overview
Code Security
Scanning & Assurance
Scan artifacts across the entire software development lifecycle
Software Supply Chain Security
Protect your code, tools, and processes
Vulnerability Management
Advanced Code-to-Cloud vulnerability management to reduce noise and fix fast
Runtime Security
Container Security
Full lifecycle advanced protection for containerized applications
Cloud Workload Protection (CWPP)
Runtime protection for every cloud native workload
GenAI Application Security
Secure GenAI Applications from Code to Runtime
Posture Management
CI/CD Pipeline Security
Automate DevSecOps
Kubernetes Security
Holistic Kubernetes Security for the Enterprise
Cloud Security Posture Management
Extend traditional CSPM with workload visibility
Solutions
Solutions
Monitor
Monitor Behavior Across Every Environment
Detect
Detect Exploitable Risk and Active Attacks
Enforce
Enforce Policy Inline at the Point of Execution
Contain
Contain Threats and Maintain Control
Compliance
Prove Compliance in the Most Regulated Environments
Hybrid and Multi-Cloud
Secure Applications Across Hybrid and Multi-Cloud
Industry
Federal
Protect Highly Sensitive Data
Financial Services
Protect FinServs From Cyber Threats
Resources
The best of cloud native
Aqua Blog
Expert insight, best practices and advice on cloud native security, trends, threat intelligence and compliance
Read the Blog
Resources
Resources Center
eBooks, Data sheets, Whitepapers, Webinars, and much more
The Cloud Native Channel
Cloud native security webinars & videos
Aquademy
The Aqua academy
Cloud Native Wiki
The educational center for everything cloud native
Company
Recognized Leadership
CISO Choice Awards
Winner for Cloud Workload Protection Platform (CWPP)
Forrester Consulting: The Total Economic Impact™ of Aqua CNAPP
90% Reduction in vulnerability research and detection time
Frost & Sullivan CNAPP report
Top innovation leader
About Us
Newsroom
Customers
Partners
Careers
Support
Services
Upcoming Events
Connect
Contact
Twitter
Facebook
Linkedin
Instagram
News
Aqua Security Turns Runtime Intelligence into Action with Agentic Response, Debuts Risk Dashboards
Aqua Security Doubles Down on Runtime to Deliver Measurable Cloud Risk Reduction
ActiveState Joins Trivy Partner Connect to Cut CVE Noise and Reduce Alert Fatigue for Developers
Get Started
Aqua Cloud Native Blog
› Tags: Aqua Trivy
Expert insight, best practices and advice on cloud native security, trends, threat intelligence and compliance.
Aqua Trivy
When Security Scans Break the Brain: Solving Trivy’s etcd Exhaustion Problem
This post comes from Pushkar Joglekar, Principal Security Engineer at Broadcom, where he focuses on VMware Kubernetes distributions. Pushkar is a Kubernetes security maintainer and co-author of the security chapters in Nigel Poulton’s “The Kubernetes Book.” He writes from experience securing infrastructure at scale. It starts with a failing deployment. You attempt a quick fix—maybe …
Aqua Trivy
Security That Speaks Your Language: Trivy MCP Server
What if checking your project for vulnerabilities was as simple as asking a question? Or if your coding AI agent could automatically run a scan every time you changed a Dockerfile? The new Trivy MCP Server makes all that possible, and more.
Aqua Trivy
Dev-First Security: Aqua Trivy Scanning Now in VS Code
In modern development workflows, integrating security seamlessly into the development process is crucial for delivering secure applications efficiently. Developers need security tools that work naturally within their development environment, providing immediate feedback without disrupting their workflow. The new Trivy extension for Visual Studio Code addresses this need by directly bringing comprehensive security scanning capabilities into …
Aqua Trivy
Trivy Partners with echo: Slashing CVEs at the Source
This is a guest post by Echo Imagine starting every project with CVE-free base images, without adding any extra effort or tooling to your workflow. As developers and security teams, we know how hard it is to shift left when the base you’re building on is already vulnerable. That’s why we’re excited to be a …
Aqua Trivy
Trivy VEX Hub:The Solution to Vulnerability Fatigue
VEX (Vulnerability eXploitability Exchange) is an emerging industry standard for communicating the relevance and impact of security vulnerabilities on software artifacts. This approach allows software maintainers to indicate when a specific vulnerability in a software dependency is irrelevant to their software due to the specific use case of that dependency. By conveying this crucial information …
Aqua Trivy
Scanning KBOM for Vulnerabilities with Trivy
Early this summer we announced the release of Kubernetes Bills of Material (KBOM) as part of Trivy, our all in one, popular open source security scanner. In the blog we discussed how KBOM is the manifest of all the important components that make up your Kubernetes cluster: Control plane components, Node Components, and Addons, including …
Need to secure enterprise workloads?
Aqua Cloud Native Application Protection Platform (CNAPP)
Go cloud native with the experts!
Get Demo