#4
Dark Reading
general
March 11, 2026 at 20:22 UTC
Xygeni GitHub Action Compromised Via Tag Poison
By Alexander Culafi
AI Summary
AppSec vendor Xygeni's GitHub Action was compromised via tag poisoning attack, with attackers operating an active C2 implant for up to a week. The xygeni/xygeni-action repository was targeted, potentially affecting software supply chain security for organizations using this GitHub Action.
Relevance score: 88.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →