GitHub Actions abused by Megalodon
A large-scale automated GitHub backdooring campaign was caught pushing thousands of malicious commits into public repositories while posing as routine CI/CD upkeep. Researchers at SafeDep observed the campaign, Megalo
Original Disclosure
https://www.csoonline.com/article/4177124/github-actions-ab…
Severity
high
Sector
tech
Disclosure date
May 26, 2026
Indexed
17 hours, 33 minutes ago