<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #GitHub Actions</title><description>Cybersecurity articles tagged #GitHub Actions on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>ChainDrop npm Worm: Self-Propagating Software Supply Chain Threat</title><link>https://runtimerebel.com/blog/chaindrop-npm-worm-self-propagating-software-supply-chain-threat</link><guid isPermaLink="true">https://runtimerebel.com/blog/chaindrop-npm-worm-self-propagating-software-supply-chain-threat</guid><description>Analyze the ChainDrop self-propagating npm worm infecting major packages, harvesting credentials from memory, and compromising CI/CD pipelines.</description><pubDate>Fri, 07 Aug 2026 02:13:34 GMT</pubDate><category>Supply Chain Attack</category><category>Malware</category><category>NPM</category><category>GitHub Actions</category><category>Credential Theft</category></item><item><title>Cloudflare&apos;s Flue Automates Open Source Issue Triage</title><link>https://runtimerebel.com/blog/cloudflare-s-flue-automates-open-source-issue-triage</link><guid isPermaLink="true">https://runtimerebel.com/blog/cloudflare-s-flue-automates-open-source-issue-triage</guid><description>Cloudflare details how its Flue framework automates Astro&apos;s GitHub issue triage, significantly reducing open issues and improving maintainer efficiency.</description><pubDate>Thu, 06 Aug 2026 10:32:27 GMT</pubDate><category>Open Source</category><category>GitHub Actions</category><category>AI Automation</category><category>Issue Triage</category><category>Cloudflare Flue</category></item><item><title>Defending Against the 1,444% Surge in Open Source Supply Chain Attacks</title><link>https://runtimerebel.com/blog/defending-against-the-1444-surge-in-open-source-supply-chain-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/defending-against-the-1444-surge-in-open-source-supply-chain-attacks</guid><description>GTIG reports a massive 1,444% spike in open source repository compromises. Learn how to mitigate threats from actors like UNC6780 and MIDNIGHT NEPTUNE.</description><pubDate>Thu, 30 Jul 2026 14:10:41 GMT</pubDate><category>UNC6780</category><category>MIDNIGHT NEPTUNE</category><category>Open Source Security</category><category>GitHub Actions</category><category>NPM Security</category></item><item><title>GitHub Actions Runners Weaponized to Attack cPanel and WHM Servers</title><link>https://runtimerebel.com/blog/github-actions-runners-weaponized-to-attack-cpanel-and-whm-servers</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-actions-runners-weaponized-to-attack-cpanel-and-whm-servers</guid><description>Attackers are leveraging GitHub Actions runners and compromised Packagist packages to launch distributed attacks against cPanel and WHM server instances.</description><pubDate>Thu, 23 Jul 2026 14:05:01 GMT</pubDate><category>GitHub Actions</category><category>Packagist</category><category>cPanel</category><category>WHM</category><category>Supply Chain Attack</category><category>PHP</category></item><item><title>GitHub Actions Attack Patterns Evade CI Security Scanners</title><link>https://runtimerebel.com/blog/github-actions-attack-patterns-evade-ci-security-scanners</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-actions-attack-patterns-evade-ci-security-scanners</guid><description>Learn how sophisticated GitHub Actions attack patterns bypass traditional CI security scanners, exposing CI/CD pipelines to supply chain risks.</description><pubDate>Tue, 07 Jul 2026 14:38:51 GMT</pubDate><category>GitHub Actions</category><category>CI CD Security</category><category>Supply Chain Security</category><category>Security Scanning</category><category>Code Integrity</category></item><item><title>Cordyceps: Defending Against Malicious Pull Requests in CI/CD</title><link>https://runtimerebel.com/blog/cordyceps-defending-against-malicious-pull-requests-in-ci-cd</link><guid isPermaLink="true">https://runtimerebel.com/blog/cordyceps-defending-against-malicious-pull-requests-in-ci-cd</guid><description>The Cordyceps campaign highlights critical CI/CD vulnerabilities in GitHub Actions, targeting high-profile projects like Apache Doris and Cloudflare Workers SDK.</description><pubDate>Wed, 24 Jun 2026 09:23:01 GMT</pubDate><category>GitHub Actions</category><category>CI CD Security</category><category>Supply Chain Attack</category><category>DevSecOps</category><category>Cordyceps</category></item><item><title>Anthropic Claude Code GitHub Action Flaw Enables Repo Hijacking</title><link>https://runtimerebel.com/blog/anthropic-claude-code-github-action-flaw-enables-repo-hijacking</link><guid isPermaLink="true">https://runtimerebel.com/blog/anthropic-claude-code-github-action-flaw-enables-repo-hijacking</guid><description>A critical flaw in Anthropic&apos;s Claude Code GitHub Action allowed attackers to hijack public repositories using malicious issues, posing supply chain risks.</description><pubDate>Thu, 04 Jun 2026 17:08:52 GMT</pubDate><category>Anthropic</category><category>Claude Code</category><category>GitHub Actions</category><category>CI CD Security</category><category>RyotaK</category></item><item><title>Megalodon Supply Chain Attack Infects 5,500+ GitHub Repositories</title><link>https://runtimerebel.com/blog/megalodon-supply-chain-attack-infects-5500-github-repositories</link><guid isPermaLink="true">https://runtimerebel.com/blog/megalodon-supply-chain-attack-infects-5500-github-repositories</guid><description>Attackers used automated commits to inject malicious GitHub Actions workflows into 5,500+ repositories, targeting CI/CD secrets and sensitive tokens.</description><pubDate>Mon, 25 May 2026 09:28:56 GMT</pubDate><category>GitHub</category><category>Supply Chain Attack</category><category>Megalodon</category><category>GitHub Actions</category><category>Credential Theft</category></item><item><title>Megalodon Campaign: 5,561 GitHub Repos Hit by Malicious Workflows</title><link>https://runtimerebel.com/blog/megalodon-campaign-5561-github-repos-hit-by-malicious-workflows</link><guid isPermaLink="true">https://runtimerebel.com/blog/megalodon-campaign-5561-github-repos-hit-by-malicious-workflows</guid><description>Automated Megalodon attack pushes 5,718 malicious commits to GitHub repositories to exfiltrate secrets via GitHub Actions workflows.</description><pubDate>Fri, 22 May 2026 12:58:34 GMT</pubDate><category>Megalodon</category><category>GitHub Actions</category><category>CI CD Security</category><category>Supply Chain Attack</category></item><item><title>Grafana Breach After TanStack Attack: Token Rotation Failure</title><link>https://runtimerebel.com/blog/grafana-breach-after-tanstack-attack-token-rotation-failure</link><guid isPermaLink="true">https://runtimerebel.com/blog/grafana-breach-after-tanstack-attack-token-rotation-failure</guid><description>Grafana suffered a data breach due to a GitHub workflow token not rotated after the TanStack npm supply-chain attack, impacting user data. Learn the details.</description><pubDate>Wed, 20 May 2026 17:12:03 GMT</pubDate><category>Grafana</category><category>TanStack</category><category>NPM</category><category>Supply Chain Attack</category><category>GitHub Actions</category><category>Token Rotation</category><category>Data Breach</category></item><item><title>GitHub Actions Supply Chain Attack: actions-cool/issues-helper</title><link>https://runtimerebel.com/blog/github-actions-supply-chain-attack-actions-cool-issues-helper</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-actions-supply-chain-attack-actions-cool-issues-helper</guid><description>Analysis of the actions-cool/issues-helper supply chain attack where tags were redirected to steal credentials. Learn how to detect and mitigate this threat.</description><pubDate>Tue, 19 May 2026 09:20:28 GMT</pubDate><category>GitHub Actions</category><category>Actions Cool</category><category>Supply Chain Attack</category><category>Credential Theft</category></item><item><title>Gemini CLI Critical RCE Fix: Patching the @google/gemini-cli Flaw</title><link>https://runtimerebel.com/blog/gemini-cli-critical-rce-fix-patching-the-google-gemini-cli-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/gemini-cli-critical-rce-fix-patching-the-google-gemini-cli-flaw</guid><description>Google patches a CVSS 10.0 flaw in Gemini CLI tools that allowed unprivileged attackers to execute commands in CI/CD environments via malicious configurations.</description><pubDate>Thu, 30 Apr 2026 08:52:38 GMT</pubDate><category>Google Gemini CLI</category><category>GitHub Actions</category><category>Google Gemini</category><category>CI CD Security</category><category>RCE</category></item><item><title>OpenAI Revokes macOS App Certificate Following Supply Chain Attack</title><link>https://runtimerebel.com/blog/openai-revokes-macos-app-certificate-following-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/openai-revokes-macos-app-certificate-following-supply-chain-attack</guid><description>OpenAI revokes its macOS app signing certificate after a GitHub Actions workflow downloaded a malicious Axios library version during a supply chain incident.</description><pubDate>Mon, 13 Apr 2026 08:48:46 GMT</pubDate><category>OpenAI</category><category>macOS</category><category>Axios</category><category>GitHub Actions</category><category>Supply Chain Security</category></item><item><title>Axios NPM Supply Chain Attack Bypasses GitHub Actions CI/CD</title><link>https://runtimerebel.com/blog/axios-npm-supply-chain-attack-bypasses-github-actions-ci-cd</link><guid isPermaLink="true">https://runtimerebel.com/blog/axios-npm-supply-chain-attack-bypasses-github-actions-ci-cd</guid><description>A sophisticated supply chain attack targeted the Axios NPM package, leveraging a compromised token to bypass GitHub Actions CI/CD and deploy malicious versions.</description><pubDate>Wed, 01 Apr 2026 12:28:22 GMT</pubDate><category>Axios</category><category>NPM</category><category>Supply Chain Attack</category><category>North Korea</category><category>GitHub Actions</category><category>CI CD</category></item><item><title>TeamPCP Supply Chain Attacks Target Docker Hub, PyPI, and VS Code</title><link>https://runtimerebel.com/blog/teampcp-supply-chain-attacks-target-docker-hub-pypi-and-vs-code</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-supply-chain-attacks-target-docker-hub-pypi-and-vs-code</guid><description>TeamPCP expands supply chain attack tactics from GitHub Actions to Docker Hub, PyPI, and VS Code extensions, collaborating with the Lapsus$ hacking group.</description><pubDate>Wed, 25 Mar 2026 12:24:38 GMT</pubDate><category>TeamPCP</category><category>Lapsus</category><category>Supply Chain Attack</category><category>Docker Hub</category><category>GitHub Actions</category><category>VS Code</category></item><item><title>Trivy Supply Chain Attack: TeamPCP Pushes Infostealer via GitHub</title><link>https://runtimerebel.com/blog/trivy-supply-chain-attack-teampcp-pushes-infostealer-via-github</link><guid isPermaLink="true">https://runtimerebel.com/blog/trivy-supply-chain-attack-teampcp-pushes-infostealer-via-github</guid><description>Threat actor TeamPCP compromised the Trivy-action repository to distribute infostealer malware through GitHub Actions, targeting CI/CD pipelines and secrets.</description><pubDate>Sat, 21 Mar 2026 20:08:15 GMT</pubDate><category>Trivy Scanner</category><category>GitHub Actions</category><category>TeamPCP</category><category>Infostealer</category><category>CI CD Security</category></item><item><title>75 Trivy-Action GitHub Tags Hijacked in Supply Chain Attack</title><link>https://runtimerebel.com/blog/75-trivy-action-github-tags-hijacked-in-supply-chain-attack</link><guid isPermaLink="true">https://runtimerebel.com/blog/75-trivy-action-github-tags-hijacked-in-supply-chain-attack</guid><description>Attackers hijacked 75 tags in Aqua Security&apos;s Trivy GitHub Actions to exfiltrate CI/CD secrets, marking the second major breach in a single month.</description><pubDate>Fri, 20 Mar 2026 20:11:11 GMT</pubDate><category>Aquasecurity</category><category>Trivy Action</category><category>GitHub Actions</category><category>Supply Chain Attack</category><category>Secret Theft</category></item><item><title>Tag Poisoning Compromises Xygeni GitHub Action, C2 Implant Active</title><link>https://runtimerebel.com/blog/tag-poisoning-compromises-xygeni-github-action-c2-implant-active</link><guid isPermaLink="true">https://runtimerebel.com/blog/tag-poisoning-compromises-xygeni-github-action-c2-implant-active</guid><description>Attackers compromised the `xygeni/xygeni-action` GitHub Action using tag poisoning, deploying a C2 implant for up to a week. Users must verify integrity and review logs.</description><pubDate>Thu, 12 Mar 2026 00:30:26 GMT</pubDate><category>GitHub Actions</category><category>Supply Chain Attack</category><category>Tag Poisoning</category><category>Xygeni</category><category>C2</category></item></channel></rss>